I gotta say, the open source community response to the XZ issue and auditing code changes for the specific threat actor has been incredibly good overall.