Yes, and also run routine tests and check-ups!

I personally check my websites and apps every week to see if anything might have slipped through.

It may not protect me from the next malicious NPM package, but it's something.