- Carl Sagan
the npm ecosystem takes this quite literally, for better or worse.
Vendoring/copying them is another way to achieve this (and means you don't need to depend on npm or its lockfiles).
Regardless, those libraries are your problem whether you vendor/copy them or not.
Read more: https://research.swtch.com/deps