Earlier quoted context omitted.
The "biggest" problem in the JavaScript ecosystem (NPM) is that dependadabot doesn't know how to discriminate between dependancies and devDepandancies. I don't really care if jest includes a package that has a regex issue. It's not production code. I do care if babel introduces a backdoor, but somehow they're treated with equal importance.
It depends, attacks via build pipelines can be devastating.
Unfortunately it’s not clear cut that we don’t have to worry about devDependencies vulnerabilities.