That might change the odds, but unless you fork diligently (and monkeypatch each and every future vulnerability) you might ship a compromised fork forever.
Except most of the attacks so far has not landed actually source code changes to git IIRC. They have targeting the release files directly.
Except most of the attacks so far has not landed actually source code changes to git IIRC. They have targeting the release files directly.