You're right about package.json, pnpm-lock etc though, but those are easy to filter out if the project in question uses them.
You're right, perhaps I should have said CHANGELOG etc.
Although some projects e.g. bump version numbers in README or add extra one-liner examples ....
This post is about exploring code, not documentation. Nobody is going to warn you about the README unless it is super outdated.
You're right about package.json, pnpm-lock etc though, but those are easy to filter out if the project in question uses them.