For an important production system, you probably want the source of any third-party packages on which you depend to be in Git (or another SCM system) that you control.

You might also want to audit those packages yourself, as well as audit any new version changes to them, before you push to production.

After you do those things in SCM, depending how you do it, you *might* find it's more convenient to simply load the third-party code you need using the module system `require` only, without an additional package system.

