The many (many) ways I've backdoored your dependencies and other supply chain at
kerkour.com
kerkour.com
It all seems a bit hopeless, I refuse to believe anyone who claims to audit everything and every update - and would they have caught xz's backdoor anyway?
my 2 cents are that it is not theoretically possible to handle and actually fight the problem of _too many dependencies_. we all need them to move quickly.
But, there must be a balance.
remark: just look at the FE framework / packages world (eco system), this is too much, and most are not needed.
It's more like a "hope to" than an actual solution
[0] That really is the only fail-closed way to do it. Everything else is theater... good theater, but theater.
EDIT: Btw, I do not mean to be dismissive towards lower-level/higher-sophistication security issues like side-channels, etc... but that's peanuts to ordinary Bad Guys. (Nation states might be more interested in advanced things). Most Interweb Bad Guys use very simple techniques, like bad writing in a scam email.
...well, I guess if your project is mostly about its internal business logic, not interacting/integrating with the wide world via the loads of weird and poorly implemented protocols and points, then you could be. But is this where the money are?
Also I read the article just to see if that poor grammar was directly copied and pasted from it, and to save anyone else the time, it was. The article wasn't proofread. Just made as clickbaity as possible and posted.