This is not true for a lockfile, where the whole point is to capture the specific versions at the point in time that the generation is done.
The benefit of the contributor committing the lockfile is that it encodes the exact combo of dependencies that worked at the time the related code changes were made (in the same PR).
This means other project maintainers aren't left scratching their heads trying to figure out why a PR worked on your machine but fails in CI.