Dependabot has to be used because of the threats. However everyone automating and moving to latest is also a threat. SolarWinds/VMWare/USGov hack [3] was all related to CI builds and automated "trust", ended up infecting tens of thousands of systems that thought they were secure with SOC2. SOC2 ends up making enterprises "trust" many third parties. What happens when dependabot is an attack vector as well...
The log4j/Log4Shell [4] issue shows how long exploits can go on without detection or automated fixes. Node is filled with dependency issues and that is just the known exploits besides all the "telemetry". [5]
Any third party or dependency is a potential attack vector, and dependency saturation is adding lots of tedium to shipping. So much time goes to just updating libs it is a bit of a tragic comedy.
[1] https://en.wikipedia.org/wiki/DLL_Hell
[2] https://en.wikipedia.org/wiki/Dependency_hell
[3] https://en.wikipedia.org/wiki/2020_United_States_federal_gov...
[4] https://en.wikipedia.org/wiki/Log4Shell
[5] https://en.wikipedia.org/wiki/Npm_(software)#Notable_breakag...