LSA UI/UX: Architecture - Security

How do you handle security issues with open-source packages?

The Pega Platform already uses more a lot of open-source packages. React is no different.