Sorry I didn't have the patience to fully read this click bait. If you use 3rd party packages (aka FOSS, Open Source, whatever they call it) those vulnerabilities are a by product of using the 3rd party package, it is the cost of doing business. They make SCA tools, even free ones to identify these issues. IMO, importing, updating, and using 3rd party packages in your development process are a part of technical debt and cyber hygiene, nothing more nothing less.<p>TL;DR Don't be dumb, update your packages and don't use vulnerable ones.