3 ways to mitigate risk when using private package feeds

Software today has become an assembly of components from a wide range of sources. Individual packages may be developed in-house, acquired from third-parties, or downloaded from free and public sources. The security risks of these sources are straightforward to understand in isolation.
