Has anyone thought of having an agent review all dependency upgrades before upgrading?

I feel like that would at least catch some of these

Yes, I do this. It absolutely would catch some of these.

[dead]