Github is aimed at software developers. GitHub threads will therefore tend towards discussions based on what is mathematically possible drowning out conversations about what is socially desirable. This is normal; computer programmers are required to argue with an electric abacus all day and it is a notoriously finicky and uncompromising device.
@shadowfirebird @luciferMysticus yeah, I know that well. I work professionally on software that I consider categorically dubious - an autoupdater - and I refuse to let it do anything other than update exactly what the user installed. (Not a hard sell, my teammates are with me on this.)
But we can’t close “all possible avenues for silent remote code execution” when it exists for the purpose of silent remote code execution. (We work damn hard to ensure it’s the right code though)