With things necessary for a dev env, like read/write access to source control, attackers can get access to internal data, and push malicious code that gets run in a prod env anyway.
If you want to make the claim that using react is an insane indefensible choice from a security standpoint, you are being idealistic at best.
Telling people not to use react does not help anyone, and that type of recommendation causes reputational damage to the security industry.