Yeah unfortunately these numbers don't really allow any conclusions to be drawn at all.
Also they're not really related to supply chain security which is more about deliberate subterfuge. I think the interesting stat there would be how many authors are being trusted typically for each crate.
They wanted me to make some changes and with the normal workflow that's just
git commitandgit push. Withgit send-emailI have no fucking idea and it got beyond the point where I had enough cared enough to fight the process.