> it's not something you can worry about if you want to retain your sanity.
I build my nodejs/npm stuff in containers. Actually I build almost everything that way.
There are a lot of advantages in addition to the security gains, such as that I don't need to rely on every javascript programmer in the world understanding semver (they don't, and I have wasted more of my "sanity" on tracking down API changes and sloppy type contracts than I ever have spent cleaning up after malice.