> countless articles explaining what should be done instead (e.g. https://kerkour.com/rust-stdx)
Don't make me tap the sign: https://news.ycombinator.com/item?id=41727085#41727410
> Centralized package managers only add a layer of obfuscation that attackers can use to their advantage.
They add a layer of convenience. C/C++ are missing that convenience because they aren't as composable and have a long tail of pre-package manager projects.
Java didn't start with packages, but today we have packages. Same with JS, etc.
Or from another angle, dpkg/apt is the package manager for C/C++ ...