It's particularly 'funny' how people who have been complaining about dependencies for years and how they're too big a risk and you can't trust anyone to get it right and you're irresponsible if you're use them, etc. etc. etc.
... are now singing the praises of a *known and documented* lying and plagiarism machine that has absolutely no provenance tracing whatsoever, nor any sort of isolation of the third-party code, nor any understanding of the problem domain, nor any way to even *talk about* the unmanaged dependencies it dumps into your code base with a shared language (like you can do with, say, package names)