https://committing-crimes.com/articles/2024-09-09-jitpack/
The infosec hell was never users writing down their password in a post-it stuck to their monitor.
The true infosec hell is developers trusting centralized repositories of "open source" that nobody reads nor audits.
Again I have to battle against devs that, for pure convenience and laziness, put users and the company at the mercy of any random of the internet, with the willing to perform a supply chain attack.
