@andrewnez That's a nice conundrum:
Declare a tight version range and get hit by vulnerabilities because new versions are not downloaded;
Or accept (patch) updates and get hit because a vulnerable update is downloaded (f.e. due to a supply chain attack).