Let's say hypothetically that it's a bad strategy to give your employee a C compiler and tell them to write code. Now, if you instead gave your employee a C compiler and told them to write code with vigilance and discipline, is that somehow now a good strategy? I don't think "Lack of vigilance and discipline" is a correct or incorrect diagnosis. I think it's a useless diagnosis.
> "It is all but impossible to keep track of what you depend on, and how safe it all is"
I think this space is ripe for exploration. Imagine a world where you could depend on your choice of JSON parser. One such JSON parser is allowed to perform arbitrary IO, and another is disallowed from doing so - at a language level. Would you ever pick the first over the second? Being able to distinguish one from the other would go a long way towards feeling safe about dependencies. From a safety perspective, it wouldn't even matter how much extra transitive crap the parser pulls in. If someone hijacks the 'isEven' package, what's the worst that could happen? Go into an infinite loop or return the wrong value? Both of these would be immediately flagged by the most casual level of tests, and be far preferable than abitrary code execution.