There's been a ton of conversation about the xz exploit, but the real reason this kind of thing could even happen is because of *human* vulnerability, not a technology vulnerability. So we have to take a deep look at how we truly support the people who make open source happen. Here's the real, substantive investment @devs has been providing: https://www.fastly.com/blog/what-can-you-actually-do-to-reduce-the-threat-of-hacks-like-xz