Definitely the pattern we are trying to help folks embrace with
@tidelift by giving the tools you need as an organization to define a catalog of open source dependencies for your applications but also, very importantly, human enhanced data from the creators of that software
the most common example of that behavior these days is the netflix-style 'paved roads,' which is to say an IT-tested and backed core platform which is recommended. if unique requirements force a team off that road, so be it, but then they're on their own for literally everything.