Hi, I haven't messaged on this lost before but may as well now, I am happy to provide help with any moderation or implementations if they are needed, I think there could be a system similar to how nixpkgs is handled, where you require confirmation from trusted contributors to actually make your first contribution.
We could maybe implement a system similar to what nixpkgs uses which is all based on github, needing people to make PRs to add and update software, which does help prevent malicious pushes, there could maybe be a similar idea implemented where people need to have someone trusted to allow them to contribute, but of course this may require more manpower and maintenance than is available, and likely has more issues than I can think of right now. We might be able to do something similar to the package maintainer applications ( but less strict) to choose people to certify others and watch contributions to try and minimise the chance of bad actors being able to take over. I am happy to recieve any feedback as there are probably more logistical issues I can't think of right now, and am just adding my suggestion and volunteering my support. Isaac
signature.asc
Description: PGP signature
