Supply chain security6 min readLayered defense for dependencies: Why dependabot needs an upstream gatekeeper