If Socket is willing to flag suspicious packages for us there isn't really a downside.
It wouldn't replace any existing security controls and would just be an additional layer. The worst case scenario would be that nothing changes and if it flags even one malicious package it's a net positive. And even if their corporate generosity runs out, we are just back where we started. We aren't any less secure than we would be if we never went with them. I really don't see why we shouldn't give it a try. -- Borna Punda
