I'm working on a large (at least 300k+ loc) Django code base right now and we have 32 direct dependencies. Mostly stuff like lxml, pillow and pandas. It's very easy to use all the nice Django libs out there but you don't have to.
You just keep up as you go, as long as you keep things close to the framework it's fine.
He said "Updating a project that was started 5-6 years ago takes a lot of time."
The answer is the same in both cases: acquire some discipline and treat maintenance with the respect it deserves.
Obviously there are some dependencies that you cannot easily avoid (like the things you mention). On the other hand there is a lot off stuff used that is not that hard to avoid - things like wrappers for REST APIs are often not really necessary.