Could you please explain a little more. I can use such practice in my dev workflow.
So any third party code changes end up in git commits and are easily visible and reviweable.
So running npm update/upgrade includes the code that changed in the dependencies in the commit.
You would `npm install` and then `git commit`. That's why npm didn't have a lock file back then. Git was the lock file.
another rather simple solution is a git mirror of each package, then point npm to a git url
In cases like that it helps to do npm install on the CI and make sure you end up with identical code. Decent trade-off.