And it doesn't address the semver malware injection bug demonstrated by colors author. Funny isn't it, any one of the thousands of npm package authors can inject a malware into our computers and nobody gives a shit.
[Not a fan of Bun] In Bun, you can pin versions with package.json just like in node.js
What would address the malware injection when someone chooses to auto-update packages as part of a build?