"Don't just grab random stuff off the internet": What Chainguard found in 52,000 open-source packages The New Stack