upvote
Your question feels insane to me for production environments. Why aren't you doing a version cutoff of your packages and either pulling them from some network/local cache or baking them into your images?
reply
Aforementioned security vulnerabilities don’t strike as a potential reason to you?
reply