It's time for someone to make a Redhat, but for "safe" open source software libraries. My big enterprise would sign up for it in a heartbeat. We'd pay for access from an alternative NPM registry where everything is at least semi-vetted - someone at least looks at diffs before new versions get updated and made available. Sure, the "safe" repo wouldn't have as nearly as many packages as the main NPM repo, but if it had…
Imagine if npm allowed organizations to publish "vetted pointers" to packages. So redhat could publish a "{redhat}colors", which would include only the vetted versions.
When installing, you could choose to setup your installation to allow "redhat-vetted" versions only. And that would apply even to sub-dependencies.
This becomes a community tool if "redhat" could tell npm to vet anything vetted by another org.