Fortunately, they fixed dependency management first, so you can simply stop updating any dependency that adopts generics!
Libraries that do release security updates, but introduce new language features like generics in those point-releases also shouldn't be trusted, and have no place in production. Why should I upgrade my language version to get a security fix?