Transitive dependencies
Most of the code in a modern application arrived as a dependency of a dependency.
Nobody chose it, nobody reviewed it and it has the same privileges as the code that was written deliberately. The practical consequence is that your security posture is largely determined by decisions made by people you have never heard of, which is why inventory matters more here than review.
Checked against the primary source.
