A full-stack developer discovers a critical security vulnerability in a third-party library used in production. What is the FIRST action they should take?
-
A
Immediately remove the library without testing
-
B
Assess the risk and notify the team lead before making changes
-
C
Patch the library yourself without informing anyone
-
D
Delete the affected endpoints to prevent exploitation