Indeed, the author of this package is not at fault here. It is the responsibility of the users depending on this package to check in all their dependencies and ensure to have reproducible builds.
I think many maintainers would have done the same.
I think many maintainers would have done the same.
I for sure miss old times when I got .Net framework, maybe some library from 1 or 2 3rd party vendors and I had all I needed for development.
Of course in this case this is made worse by the fact that Javascript is so under-featured by default that you have to pull a ridiculous amount of dependencies to do anything which makes it a lot harder to audit everything. Besides since the language is so dynamic it's easy to write a very small, very powerful "shellcode" that can hook itself up anywhere in the software stack.