It's 2005 again. #Security bugs everywhere. Supply chain security erosion: many developers are apathetic or passive about security.
Here are some good ways for your dev team.
1. Dependency quarantaine
#Python:
Switch to uv
uv lock --exclude-newer $(date -d "7 days ago" +%Y-%m-%dT%H:%M:%SZ)
#Javascript
Switch to pnpm
npm-workspace.yaml:
minimum-release-age=1440
#Gradle for JVM:
Consider Renovate or Dependabot:
{
"packageRules": [
{
"matchManagers": ["gradle"],
"minimumReleaseAge": "7 days"
}
]
}
You don't need the newest features. AI models from Anthropic aren't trained that frequently anyway.
Cool down. Conservative = key.