I'm open to discussion.
1. golang source code last I checked is not even signed, and vulnerable to supply chain attacks. When I brought up this concern with the devs they lacked interest in basic proper security practice and said something like "we dont have the time to sign" or some weird comment ...