
Data shows public AI repos may be quietly becoming a supply chain risk
Over the past few years, Hugging Face has become the default destination for sharing machine learning models—much like PyPI or npm did for Python and JavaScript. It’s an undeniably powerful resource: a shared infrastructure for open research, rapid prototyping, and production deployment. But with that centrality comes a