A Spring security vulnerability is discovered in a third-party dependency used by your service. Who should be notified first?
-
A
The marketing team
-
B
The security team and service owners, then escalate based on severity assessment
-
C
Only the developer who added the dependency
-
D
No one until a patch is released