Adding a single dependency to a Node project and seeing the impact on package-lock.json is like watching a tsunami "ripple" across the entire ocean surface of the planet.

Developers using Node don't care about software supply chain security because they simply can't.