There are the other parts where really a git clone should be recursive by default pulling the submodules instead of surprising you that oh crap I have to go submodule init or whatever the command is like 50 times.
Git LFS has a similar problem, but there it does at least check out the content by default. But even there there have been too many times I've had to manually fetch things, or push things manually to different remotes.
I've never had a problem with them and don't understand why so many do.
I've always assumed the copy in .git/modules is just a cache so I don't have to re-clone the whole submodule if I switch to a commit where the submodule doesn't exist, then switch back.
git config --global --add submodule.recurse=true
will solve most of these issues.Whereas most public package registries generally don't allow removal of publicly published packages outside of special circumstances, so the references will be more durable.