You are literally criticising Webpack for its best features. Identifying outdated libraries and potentially dangerous vulnerabilities is a huge plus for Webpack. Do you think just because you include a CDN lib in the global space vulnerabilities just magically go away?
You also don't need to include packages that are poorly engineered and maintained. For what you do decide to use, you are getting visibility into the warts that you may have blissfully ignored in the past.
The issues you are describing are not really problems anymore unless you let your app get woefully out of date. The web and browsers are a moving target, so it's critical that you minimize running legacy code wherever possible. Npm/Yarn and Webpack is a huge step in making that manageable. jQuery has been on autopilot for years because it has limited usefulness. We've collectively moved on except for a few holdouts.