Not in jest. Still using node_modules from before these stunts started to occur. I recognize I am accepting risk. What I am avoiding is the surprise of a ^version-compatible file introducing new and unwanted “features”.
What do you do for security updates? There are a lot of them for NPM modules. Seems GitHub manages the database for those now:
I swear 99% of them are prototype pollution or regex DOS that don't apply to how I'm using the dependency.
See, now I can only assume you are playing with our emotions. You got the forehead vein going at first though so I'll give you that.
What about the 1% that delete data or allow for code execution?
Snapshot VM, npm install
And how do you know that is safe and hasn't exfiltrated all your data or used a VM escape exploit.
Even then, if undocumented functionality is waiting for a certain day or certain action for something to execute you have no way in asserting one way or the other if it is safe because you haven't reviewed it.