A shipping app relies on an open source library whose only maintainer went silent a year ago. A critical flaw is now public and release is in two weeks. Developers want to fork and patch it. What should the security manager do FIRST?
A. Approve the fork to keep the release on schedule
B. Assess the library's exposure and the alternatives to forking
C. Require a software bill of materials for the app
D. Block the exploit at the gateway as a compensating control
(Explain your answer for more points in the comments!)