I don't see where that assumption is baked into npm - the creator of a package declares the dependency constraints, so they are the ones making the choice which versions can be trusted well to work. You could pin all dependencies but then users would need to download tons of duplicate dependencies because of slight version differences everywhere. So it's a tradeoff, but the user makes it, not npm.