Review dependency resolution, install and build behavior, artifact provenance, release pipelines, and compromise surfaces when asked for software supply-chain assurance.