In the past few months, I’ve engaged in a number of discussions on trust. Specifically, in relation to software found on the internet, and most specifically with regard to software in public repositories like, a NuGet repo, an NPM repo, and so on. I’ll lay out some of what people have told me, offer some observations, …

