This is a standard practice in most places I have worked, CI/CD only allowed to use internal repos, and libraries are only added after clearance.
There are also tools that break CI/CD based on CVE reports from existing dependencies.
This is a standard practice in most places I have worked, CI/CD only allowed to use internal repos, and libraries are only added after clearance.