A recent IDC report indicates that a large percentage of IT teams invest over six hours each week in security patching, raising concerns about the maintenance of open-source software supply chains. Despite the popularity of open source for cost reduction and increased development speed, many organizations face challenges in sourcing dependencies, with a preference for OS packages over upstream repositories.