If you had the dependency installed before this attack, then you would still be pinned to an old safe version.