It seems we never checked in our package-lock.json, which means there's no effective checksum verification or version pinning going on.