Why is that? Do NPM package managers not create a lock file that is a text file anyone can peruse?
apps generated via create-react-app have more than 2000+ transitive dependencies.
They (you) are Blaming the dev because inherent design flaws in their development methodology.
People have been pointing out this problem with npm for years and years
Isn't that the problem? That they were running a lot of code from unpaid contributors without any guarantees (as said explicitly in the license) and then blaming those contributors when something breaks?
If I leave my garage door wide open all night and a bunch of stuff gets stolen, I'll kick myself for stupidity and vow not to do it again. I'll also call the police and hope they find the perpetrator, because there was a theft.
It is true that we as a profession need to drastically rethink our approach to dependencies and also that this author acted unprofessionally and should be condemned for his actions.
It's more like, "I let some random guy do whatever he wants to my garage door and he decides to brick it."