Security leaders face critical choices as open source projects age. Drawing from Node.js, Lodash, jQuery, and Express, this session will explore how to evaluate dependencies, spot decline, reduce risk, and see how communities maintain critical projects, and decide whether to merge, maintain, or sunset dependencies powering the enterprise.