Are you talking about requirements.txt? Requirements.txt falls short of cargo or really any other mainstream language's dependency doc (no reproducible builds, for one thing -- effectively almost as bad as undocumented).
What you mean by no reproducible builds?
Really, significantly easier to not screw up in a large org than bundler, because dependencies don't leak by default.