These days, most things that I run that aren't from my distro's repos get their own bubblewrap. On top of this, I use opensnitch. Even if I trust the application (uncommon), I never trust npm, pypi, etc. any longer. It's tedious to set this up and OSes should be helping make this easy.
Agreed. Programs like Zoom, Steam, and other closed source "apps" should always run either in a separate user account or in a bubblewrap.