The gaping hole in this write-up goes something like:
"In order to prevent a bug like this from happening in the future, we have stepped up our review process for external dependencies. In addition, we are conducting audits around code that involves sensitive information."
Of course, we all know what actually happened here:
- we did no auditing;
- because our audit process consists of "blame someone else when our consumers are harmed";
- because we would rather not waste dev time on making sure our consumers are not harmed
If you want to know why no software "engineering" is happening here, this is your answer. Can you imagine if a bridge collapsed, and the builder of the bridge said, "iunno, it's the truck's fault for driving over the bridge."