To put it another way, would you willingly download and execute 730 programs from unknown authors on your computer?
If the host of the BaaS could be trusted, and they constantly vetted all packages, isn't that possibility less risky?
Not saying, that running 700+ apps is better, just noting, that bundling as a service might not be a perfect solution either.
If we are talking about the final bundle itself being compromised, there is not really a technical solution to that other than not using dependencies.
I could see a similar situation for projects stuck on older version of node, lodash or whatever, where some tiny component break everything.
Its always fun when you have a known good build, make a change and trigger an error - only to realize the error is in your build system/dependency graph due to someone else doing testing on a different subset of versions than you need - not due to the change you just did.
Although specifically to your example of 0.8.0 to 0.8.1: that's exactly the kind of version that semver guarantees is not safe: major version 0 is the "unstable" version, and the minor/patch rules do not apply to it (see https://semver.org/#spec-item-4).
Now here is a very old and fascinating story - https://www.quora.com/What-is-a-coders-worst-nightmare/answe... and it's base, the seminal Ken Thompson Hack - https://wiki.c2.com/?TheKenThompsonHack
Sounds dangerous? It should. It is very easy to inject code in a small unknown dependency out of those thousands and effectively recreate the Ken Thompson hack.
Ultimately, these are solutions to problems that should not exist in the first place.