Random node packages processes truly sounds horrible for both security and performance, but you do want at least one LSP process spawned per filetype, right?
Separating out the LSP process from the editor is a good idea. One sure hopes the blast radius is small enough if there’s a vulnerability. My beef is really with the auto-update culture. If I can specify lock files for plugins, it helps, but no way most people are going to have the time or expertise to audit editor plugins.
I guess it’s the classic security vs. UX compromise!
Yea and updating is daunting because something always breaks. I install my vim plugins with nixos for that reason.