Why is deletion not allowed, which supply chain attacks work by deleting a release, not changing it to a malicious one?
replies(5):
What you probably want instead is one-way revocation. You place a permanent marker that says "do not use this release because it is {broken, malicious, ...}".