Seriously though, I think it's amazing that GitHub/dependabot have started doing this stuff. Real game-changer for security
But I wish SO HARD there was a way to make it clear "these dependencies might touch customers" and "these dependencies are just local, please BE CHILL"