@Foxboron @alpinelinux @archlinux That's what I'm worried about. Reviewing package bumps was less important when the maintainers were generally expected to be trustworthy and had their repurations on the line if they did anything awful. If they've outsourced that accountability to slopbots, then now bumps require serious review. And I'm worried they're not going to get that.