They're referring to supply chain attacks. Taking over open source libraries through social engineering and adding hidden malicious code. Becoming increasingly common.
One could disable updates of dependencies - especially near-real-time updates. Just updating a week after everybody else will have a lot of potential harm with libraries that have a large user base.
One could disable updates of dependencies - especially near-real-time updates. Just updating a week after everybody else will have a lot of potential harm with libraries that have a large user base.