-asking as a relatively inexperienced dev
-asking as a relatively inexperienced dev
1. Reliance on a consumer-grade component in a security-critical system holding high-value data.
The portal should have had a small, audited code base with secure coding techniques and minimal reliance on third-party components.
2. Excessive attack surface on a system holding high-value data.
The machine hosting the portal should never have had read access to SSNs. Sensitive data should have been "thrown over the wall" to a secure backend with a constrained interface. This would have greatly reduced the scope of the breach.
If you're working on something important, say critical national economic infrastructure, you do the equivalent with automated staging and testing happening before any potentially breaking changes are made to live servers.
Or... you do nothing, as the case may be...
There are services that monitor your package configuration(s) and let you know when something has been updated.
There are also mailing lists. Unless you're a Node developer, you probably only have a couple dozen dependencies in your app. Subscribe to them.
Finally, you can just check in your lockfile and update packages as part of your dev builds, then commit it whenever something changes. Your CI/CD will make sure you are always running the latest version of every application dependency in production.
Don't be so quick to judge.
I have known people without degrees (or without relevant ones) that learned on their own and were great. I have known people with a CS degree that were terrible.