The average open source (non-node) software repository uses 203 packages as dependencies. That's a lot of places where an attacker might…