Dependency updates are part of development

Keeping dependencies current is ordinary maintenance, not a security project.

Treated as something to do when there is time, it never happens, and the gap compounds until updating means a migration rather than a bump. Teams that update continuously do it in minutes. Teams that update annually spend weeks and frequently decide not to, which is how software ends up permanently exposed.

More on Secure development