Saagar Jha
(replying to Ben Cohen)
@airspeedswift It’s one of those dangerous solutions because you look at it and it’s clearly better than the alternative (maintainers burn out and don’t get paid) and we *should* do it. But it doesn’t stop supply chain attacks in general (and maybe not even this one)