@xgranade Why would you trust your own code if you know you can't trust your dependencies? I don't see how you can accept slop dependencies and avoid despair.
I think you just have to triage, adopt your most important dependencies, and see if you can build community / solidarity with others to handle the rest.