Semi-related: Microsoft is going to be (or has begun) checking for differences between published npm packages and their source control.
I got a PR in my repository a few days ago leading back to a team trying to make it easier for packages to be reproducible from source https://github.com/microsoft/Secure-Supply-Chain