@osxreverser That's not even remotely near peak. Yes, they could have done better but … nobody is buying them a separate computer to use for stuff like this and if it's a side project they're not looking for more friction.
We have this conflict all over the open source world. We could really use a well-trusted organization (CNCF, Apache, Linux, etc.) making a major effort to help maintainers adopt trusted publisher build workflows, for example, but that wouldn't be cheap or fast.
@osxreverser I'm not saying there's nothing they could have done better but that there are multiple hard problems here, none of them have easy solutions, and going around attacking OSS maintainers for not doing their unpaid labor the way you'd like is going to turn away more people than it helps.
What does work is better tools: e.g. what would it take to get to the point where most OSS maintainers have to tap a Yubikey each time they publish a release? (better, where you need n>1?)