@phnt @mia Interestingly I kind of hate those three, although Erlang and Elixir libs can somewhat be packaged (with pain, like erlang rollbacks typically means ABI break).
Go… as long as the particular application dev uses it like C (handful of cherry-picked dependencies) it's okay, otherwise /dev/mordor it goes. Interestingly same stuff for npm, but barely anyone cherry-picks dependencies in that ecosystem, hence why it gets vulns all day.