I might be thinking the wrong thing but can curl project upload curl packages to the chickencoop so that 'at least' some packages are from known source?

I know that's not your problem to fix, but still...

sure, in theory that could possibly be done. But to me that would feel like giving in to them and accepting this as how it needs to be so I will not participate in that.

so they don't care about serving malware-laden ads for decades, their app store hosting tons of copycat crap and all sorts of dodgy apps, and now this. I'm am less and less surprised by their malconduct with every passing year.

I think this isn't a nuget problem, but just package managers in general? For example, the central maven repository has loads of libraries that ship some ancient curl versions: https://central.sonatype.com/search?q=curl

I would assume the same for every other ecosystem as well

Maven Central

Maven Central: Search

Search and discover Java packages with our advanced search functionality.

It is a nuget problem for sure, but it is absolutely not exclusive to them

Elk Logo

Elk is in Preview!

Thanks for your interest in trying out Elk, our work-in-progress Mastodon web client!

Expect some bugs and missing features here and there. we are working hard on the development and improving it over time.

Elk is Open Source. If you'd like to help with testing, giving feedback, or contributing, reach out to us on GitHub and get involved.

To boost development, you can sponsor the Team through GitHub Sponsors. We hope you enjoy Elk!

Daniel RoeAnthony FuPatak三咲智子 Kevin Deng

The Elk Team