We have analysed the attacks on the software supply chains of LiteLLM and Telnyx and now recommend dependency cooldowns alongside immutable references, trusted publishers and digital attestations to secure deployments:
https://python-basics-tutorial.readthedocs.io/en/latest/packs/publish.html#securing-the-release-workflow
https://python-basics-tutorial.readthedocs.io/en/latest/packs/apps.html#updating-the-python-environment