I imagine auditing for security, and managing dependency upgrades, must both be onerously expensive time sinks?Modern devs don't care. They just install whatever, let it pull in 1000s of other packages, and continue on their merry way.
Meanwhile, a package you use today, can root your stuff tomorrow. That is, next update and bam!
Package was sold to Evil Entity, or just the dev decides to rm your drive based upon geo location.
I get paid a lot to cleanup much of this mess, and while tools such as composer and node.js are useful, they are a horrible, horrible security risks.
If you use node or composer, be prepared for dozens of updates weekly. Each update risk laden, and feature and security fixes all mashed into one.
On a large project, you'd need multiple devs, just to audit all the change.
But as you will soon see, there will be all sorts of $reasons given, which all lack understanding of how traditional Linux distros handle updates, and boil down to "not my problem" or "someome else magically makes it safe!"