Which practice reduces the risk of a supply-chain attack via Drupal's contributed module ecosystem?
-
A
Using Composer with a composer.lock file and verifying package hashes
-
B
Downloading modules as ZIP archives directly from third-party mirror sites
-
C
Installing all available modules to test features before choosing one
-
D
Disabling module update notifications to reduce noise