Some very interesting points made here by @johnmcbride on the recent core-js issue https://onengineering.substack.com/p/core-js-is-holding-the-internet-hostage
A deep dive on what's going on with Core-JS

A deep dive on core-js, its maintainer, and the JavaScript secure software supply-chain fiasco that has gotten out of control.

On Engineering