Nobody can decide on standards because everyone is greedy. Microsoft has, like, a dozen GUI platforms and they're all Windows-only. Apple doesn't even use an off the shelf rendering API. And android is... Well, android.
Sure, I would like to use the OS provided controls. And then maybe after that we can all hold hands and sing Kumbaya.
I know this isn't a silver bullet solution to supply chain attakcs, but, so far it has been effective against many attacks through npm.
https://docs.npmjs.com/cli/v8/commands/npm-config
Source: https://pnpm.io/settings#ignoredepscripts