@nprofile1q... We may need a "safetime" tracker that lets us know when there were no known widely-used packages that were compromised in a repository.
Retroactive, of course, but might be interesting like uptime. e.g. npm might have 98.5% safetime this week based on known compromises.