Now #golang has a supply chain security problem.
Github actions, terraform, go.... hmm, what do we got in common here.. treating git endpoints as trusted. But git endpoints can't have any central authority to check for malicious code! At least at #pypi you can report a package as malicious.
https://www.youtube.com/watch?v=EyO_SMl2YBk&ab_channel=CodeHead