Sure, but then you need to have a way to whitelist
The whitelist is the package-lock.json of the hashes of libraries you or a security reviewer you trust has reviewed.