This is an indictment of the designers of wild lands systems like ruby Gems and npm and a culture of pulling in hundreds of dependencies that simply cannot be verified by end users.
It's one thing if this was just for developers who made a conscious decision to use a gem or npm package, but the whole system is carried on to end users who are expected to have a build environment and pull in hundreds of unknown gems and packages which in turn pull in their own dependencies simply to deploy.
This is bad engineering and design, it not only dramatically increases the complexity of deployment and wastes millions of man hours in debugging, versioning and build issues but leaves end users exposed to security issues.