A product team used an AI coding assistant to build a payment feature and wants it in Friday's release. Nobody threat modeled the code, and the pipeline only runs unit tests. What should the application security manager require FIRST?
A. Static and dynamic scanning gates in the pipeline
B. Threat model of the feature's payment data flows
C. Senior developer review of the generated code
D. Feature flag and rollback plan for the release
(Explain your answer for more points in the comments!)