@MaddieM4@raphus.social the over leveraged transient trust relationships we have embodied in package managers and distributions with massive package sets and builds with maximum features and thus maximum dependencies, are no longer tenable. Slop exacerbates it, but even without slop we are seeing the results of that shared infrastructure being targeted by bad actors — states, criminal gangs, rent seekers.
I say this not in disagreement with
#NeverSlop as a system design principal, but to expand the understanding of the threats we face at this time.
No slop, no features designed for rent extraction, no standards that are cartel whitewashing, measure and know the cost of each dependency, and build open alternatives that are radically simpler.
For example, GameOfTrees, not git with rust and ruby toolchain dependencies. Workflows that don’t require JavaScript to collaborate.