Acknowledging the risks of open source dependencies to software supply chain security