Why 'zero vulnerability' code packages can still be a supply-chain risk

A zero-CVE badge on a software package doesn't mean it's safe — the piece argues that metric can mask real supply-chain risk.