RE: https://mastodon.social/@bagder/116280705328672025

/me flips a table
(/me very tidily puts the table back)
But when I do a release, I'm supposed to sign my tarballs with GPG, try to keep a good relationship with my distro packagers (who are awesome!), clearly version files, keep a trustworthy presence with users, so that they don't install random crap they find online…

@funkylab I guess in this case is unnecessary: one is rubbing an old lamp to get a digital genie out in the hope it will do its master bidding. All security considerations have already been "addressed".