Out of date dependencies also introduces vulnerabilities though. So you’re screwed no matter what.
Note that the distributions used by package managers such npm, pip, or cargo do not do this. So be wary of the "all old is bad and needs to be rewritten and C does not even have a proper package manager" crowd. (memory safety is a good thing though)