nostr:npub10smdhqjvt80rt7g3mgqvwhvxs4qh8few5pyfgs6wcxap7w4vrl3spfhjqm I can't follow your accusation.
The facts show that Microsoft got compromised since at least 2021-04.
There is no claim by MS I know of that GH is completely separated from MS infrastructure that got compromised.
Current NixOS setups are pulling from GitHub which belongs to Microsoft. Yes, this can be changed but that's not the point here at all.
As far as I know, you can't protect yourself from a bad actor that has more or less full access to the GH infrastructure and backends.
1/2