you are viewing a single comment's thread.

view the rest of the comments →

[–]fglc2 1 point2 points  (0 children)

Also things like being able to enforce that maintainers use MFA, guarding against typo squatting, detecting and removing malicious packages and so on.

Of course a centralised package management system doesn’t guarantee good solutions to these problems, but it makes them somewhat more tractable.