• anyhow2503@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    9 days ago

    There are some good points in it, though I wouldn’t really consider go dependencies all that decentralized in practice and I don’t understand how checksum db will protect against supply chain attacks with stolen credentials, but I admit I haven’t looked into the details.