No, this is what the lock file is for.
Indeed. What's probably needed here is a way to review a diff of the contents of the updated packages. Checking them is is just a brute-force way to do that.
something like cargo-crev for npm might be a long term solution