Lol since forever? It doesn’t verify the authenticity of anything it downloads, so its vulnerable to supply chain attacks.
Pip and crates has the same problem.
Maven is the only programing language package manager I know of that does. Otherwise, OS package managers like apt are secure, od course.
They’re exposing themselves to risk. Fortunately for them, they dont care about protecting the data of their customers.