Lockfiles protect you from someone who would publish a malware that replaces an existing version (lockfiles have hashes alongside the versions)
Lock files are used to lock dependency versions all the way down your dependency tree, not just your immediate dependencies.
Thanks everyone for pointing out this issue.
I wonder whether one of the npm alternatives has a "--sane" mode that would always pick the oldest possible dep...