Not totally: the big question remains of how a tampered-with package can reach a prominent repository.
Not totally: the big question remains of how a tampered-with package can reach a prominent repository.