It probably does get that advantage that it has had fewer supply chain attacks than npm.

I liked its scoring system for packages and "make the Typescript docs a public part of the package page" and "focus entirely on ESM-first/ESM-only packages". None of that npm does today, so JSR is still the best way I know to find modern and up-to-date/clean packages versus npm just has a nasty swamp of things still in CommonJS for no reason or that will never get upgraded out of CommonJS because the original maintainers are long gone.

I personally see it as valuable for similar reasons -- plus the ability to just import via web if a package is compatible with browsers, and it being open source and free for the community to fork and rebuild in case something like this goes south.