Lol yeah working in enterprise software for a long time, it's more like:
- Import what you think you need, let the CI do a security audit, and your senior engineers to berate you if you import a huge unnecessary library where you only need one thing
- Tree shake everything during the CI build so really the only code that gets built for production is what is being used
- Consistently audit imports for security flaws and address them immediately (again, a CI tool)
- CI
Basically just have a really good set of teams working on CI in addition to the backend/frontend/ux/security/infrastructure/ whatever else teams you have