Package dependencies can create vulnerabilities that are fiendishly hard to find and stamp out