The transitive package Magick* is indicating vulnerabilities almost weekly. After updating that package and others, our pipeline and monthly scans are already showing new vulnerabilities.
Due to company policy with regard to industry regulations on FinServ, we are not allowed to release any software to prod which contains moderate and higher vulnerabilities.
While I understand Magick and other packages are not Kentico packages, it's become a time consuming task for a small team, preventing bug fixes, kentico package updates, and feature requests from going live while multiple sites are being migrated from legacy kentico into XbyK.
The hard reference to specific package versions has lead to diminishing returns.
Environment
Xperience by Kentico version: [31.2.0]
.NET version: [9]
Execution environment: [Private cloud (AWS)]
Link to relevant Xperience by Kentico documentation