I have concerns about NPM too, but I think it is absurd to just sweat that when it has proven NOT to be the source of most of our security issues generally. We could 'fix' NPM or just not use it, and ...