Your lockfile is a supply chain attack surface you're ignoring
Lockfiles are treated as generated noise in most code reviews, but a tampered package-lock.json or pnpm-lock.yaml can silently swap a legitimate package for a malicious one without touching any source file.