I am wondering if there is a niche for a paid repository (npm or maven) that actually verifies/tests/analyzes libraries and recommends/bans libraries/versions that didn't pass such verifications. That could potentially prevent Equifax hack, Log4j, etc. Could be good for the enterprise.
I am frankly surprised that dependency attacks are not a big thing yet (or they are?) as we devs just throw in any dependency in if it looks like its doing the job.
Also many corporate repos are just a garbage bin of crap. I can quietly replace a library in the repo, make sure the projects grab my modified version before the release and rollback shortly after). I remember called this a "maven bomb" and discussed with my teammates and a manager - who didn't give a shit