chasing0entropy 13 hours ago

I don't know why git is so popular vs private repository with dependency connections that are audited and controlled (e.g. filtering out beta versions, delaying/flagging new versions syncs for vetting)

The idea of an online synced repository publicly available for any joe to sync a .5kb encoded binary update to a popular no name library that shouldn't even be a fork plus all of the other consequences therein seems like a nonstarter.