We should be auditing the integrity of PURLs for source and binaries to detect malicious backdoors or missing source code for the 5,000 most popular PURLs in major package ecosystems, and working with upstream FOSS projects and ecosystems to resolve the key security issues uncovered.
This is about running map_deploy_to_devel and analyzing results