This sounds more like a fix for an issue that should not exist in the first place. Why is npm ignoring the lock file to begin with? Why not publish and respect it on install?
In theory semver should help with this, but humans decide the semver version and it's not always possible to know the effects of a change so they may mark it as patch, but it breaks something and you get this sceanrion
Ruby gem has lock files, Python pip has lock files. I wish everyday that apt/dpkg had lock files.
The balance is between permissive versions (small install size) and pinned versions (reproducibility).
Some situations call for one, some call for the other.