@smallsees @nolan I guess in a way it's a blessing in disguise.
What it should teach developers in big companies is that *they* are responsible for vetting the dependencies in their final application.
Fixed versioning and mirroring your own repos in the build environment is something Maven used to get a lot of stick for, but I think the lessons are being re-learned about why they're important things to do.