If you're building a modern web app, you're likely using more than just JS files. The compilation target is complex, and there's room for more optimizations when the bundler is aware of the app as a whole.
Parcel is here because most people don’t need to just bundle but also a whole pipeline for optimization and extended browser support (Babel)
Parcel by itself is small, but it could potentially require a lot less packages by default if it did that with other large dependencies: Babel, SVGO, CSS Nano, PurgeCSS/UnCSS, PostHTML, which are not required if you don't use Parcel to bundle JS/SVG/CSS/HTML.
To put it another way, would you willingly download and execute 730 programs from unknown authors on your computer?
If the host of the BaaS could be trusted, and they constantly vetted all packages, isn't that possibility less risky?
Not saying, that running 700+ apps is better, just noting, that bundling as a service might not be a perfect solution either.
If we are talking about the final bundle itself being compromised, there is not really a technical solution to that other than not using dependencies.
I could see a similar situation for projects stuck on older version of node, lodash or whatever, where some tiny component break everything.
Its always fun when you have a known good build, make a change and trigger an error - only to realize the error is in your build system/dependency graph due to someone else doing testing on a different subset of versions than you need - not due to the change you just did.
Although specifically to your example of 0.8.0 to 0.8.1: that's exactly the kind of version that semver guarantees is not safe: major version 0 is the "unstable" version, and the minor/patch rules do not apply to it (see https://semver.org/#spec-item-4).
Now here is a very old and fascinating story - https://www.quora.com/What-is-a-coders-worst-nightmare/answe... and it's base, the seminal Ken Thompson Hack - https://wiki.c2.com/?TheKenThompsonHack
Sounds dangerous? It should. It is very easy to inject code in a small unknown dependency out of those thousands and effectively recreate the Ken Thompson hack.
Ultimately, these are solutions to problems that should not exist in the first place.
I wish core JS had more functionality built in to alleviate the need for all these tiny packages.
Unfortunately it does not bundle to usable file for browsers, but SystemJS and AMD, and then we are back to RollUp or Parcel or Webpack.
One day...
It's the old tradeoff: Configuration (+ installation of multiple plugins, which may all break individually) vs. one system that already just works.
I guess Parcel 2 will be better in that regard.