The first place you might start is by scanning your code for vulnerabilities. A company like Checkmarx or Snyk can scan your code repository and let you know what the vulnerabilities are within your software supply chain. They can let you know where the problems lie.
Then, you might accept that there are risky and bad dependencies in your software, and you need to keep them going regardless. In that case, you need someone who will take care of those old, unsupported packages. Aaron Mitchell, the CEO of HeroDevs, calls his company the “nursing home of the internet” — HeroDevs provides and maintains safe, updated, and secure versions of packages so you don’t have to. This lets you manage the timing on migrating away from problematic code.
Or, you might just want a low-level solution that removes much of the problem entirely. Chainguard provides container images that are stripped down, secured, and built nightly to eliminate the dependency problem. They can replace all that low-level code with hardened solutions that eliminate the problem at the operating system level.

