If you don't update your dependencies all the time, you will be vulnerable to old bugs and issues.
The current software engineering paradigm has no meaningful answer to this, no matter what "security experts" tell you. In a sane industry this realization would lead to a change of the paradigm, but people in our industry seem to be only doubling down.
"Use a build tool to do dependency checks!"
And then what?
"Only update libraries if they have vulnerabilities."
So, should this be a manual process where I have to dig through obscure warnings every time I build something?
"No, you can automate it!"
Congrats, you've just outsourced the decision making process about which versions of libraries to use to some 3d party. You've also made your build process reliant on yet another online service.
"But it's not a hard dependency, you can still build if the 3d party service is off."
So the exact software you compile will depend on whether or not you can connect to a 3d party service? Do you understand the actual implications of this?
Etc. People with clever advice don't seem to think it through. We're fighting fragile complexity of too many tools ducktaped together by ducktaping more tools to the whole setup. Again and again and again.