Discuss the latest trends in open-source library attacks: dependency confusion, malicious packages, hallucination of dependencies by AI tools. We will explain how to take advantage of a Software Composition Analysis tool to protect against these risks and eliminate vulnerabilities. We will also explore the risks of licensing code dependencies on companies' intellectual property.