It won't protect against a newer version of an established library introducing malicious behaviour.
Lock files are used to lock dependency versions all the way down your dependency tree, not just your immediate dependencies.
Thanks everyone for pointing out this issue.