It seems in some large businesses code ownership is an issue too.
If you NPM import that's now part of your SCA/SBOM/CI to monitor and keep secure.
If you write code, it's now your problem to secure and manage.