Again, how upstream approached the problem of random-someone uploading a repository version of a system package? Why we're using much less efficient approach here?