open source package manager risks