1) As the developer if you focus on hardening, you might be too late to release.
2) People downloading shiny new libs/files/programs constantly.
3) Influx of people not that versed in the basics of computer security playing around with local LLM models, image generators, etc.
Those same points (but the NodeJS/NPM version of them) is a lot of why that ecosystem is having security and reputation issues as well.
1) As the developer if you focus on hardening, you might be too late to release.
2) People downloading shiny new libs/files/programs constantly.
3) Influx of people not that versed in the basics of computer security playing around with local LLM models, image generators, etc.