Stray thought: adding a library the PR submitter controls would be a good starting point for an XZ/SSH-style supply chain attack: badger & threaten the maintainers to add the dependency, and then sneak something into a future library update.
Who would you cite as having done significant investigative reporting on Youtube? (setting aside the Pulitzers for poetry, music, fiction, non-fiction, none of which would be first published there...)
I have rarely read a smugger blog post than this one. While the author isn't wrong about Final Frontier and their ultimately doomed practice of completing Kickstarter N with the funds from Kickstarter N+1, I find it hard to believe that companies like Cephalofair or Stonemaier are unaware of an escape hatch as simple as using a different freight code.