I just think the framing that npm is so bad is really flatly invalid.
Is it really though if we're getting thousands of compromised packages regularly?
You can do all the right things and still be legit problematic.
(Rust has a similar culture, to be clear. I don’t think it’s a death knell.)