Earlier quoted context omitted.
At this point I trust the Go modules supply chain considerably more than any free distro's packaging, which is ultimately pulling from GitHub anyway.
This is plain false. Most production-grade distribution do extensive vetting of the packages, both in terms of code and legal. Additionally, distribution packages are tested by a significant number of users before the release. Nothing of this sort happens around any language-specific package manager. You just get whatever happens to be around all software forges. Unsurprisingly, there has been many serious supply cha…
MVS also prevents unexpected upgrades just because someone deleted a lockfile.