I think that the whole concept of sharing user repos to install packages is sadly not really good anymore. Because now it suddenly exposes that there is usually neither a trust anchor to that repo, nor an established review and fix process for such things.
I‘d say, just use the community maintained official package sources for now.






Because of the users that don’t want to change how they work. But still would like not to be owned by the onslaught of LLM wielding hackers