If you want 100% confidence in being able to reproduce the specific bytes included in a deployment, you should use an additional mechanism that can verify contents rather than versions. For example, Amazon machine images, DigitalOcean snapshots, Heroku slugs, or simple tarballs."
https://docs.npmjs.com/misc/faq#should-i-check-my-node-modul...
Either because authors "bugix" their existing versions and don't bother to increase the version number. Or because a malicious network actor delivered modified code.
That's why I prefer to add a SHA-256 hash/checksum to every downloaded dependency file. In some settings that hash might be more important than the actual version number.
But I'm still uneasy with this, as the crypto hash approach provides some more safety features. For example, it protects against attacks the NPM platform itself (assuming they happen after you incorporated the library into your project). Also, it enables us to download the package from any other source (e.g. some archive/mirror), via plain HTTP, while still being safe from downloading a modified package.
That's why I still wish the crypto hashes were included in package.json (automatically on "install --save-exact", of course).