The last third of that is an interesting discussion about whether it actually pays off to use the latest versions of dependencies based on the data that #Sonatype gathers from #MavenCentral and other repositories
https://opensourcesecuritypodcast.libsyn.com/2026-state-of-the-software-supply-chain-with-brian-fox