Well for one, one corrupting package , can bring the whole pkg infracture down, by corrupting the sqlite database, which is bad.
Second somehow it was pushed on the servers without verifying, which is bad.
Third people on quarterly could not upgrade their packages for one day, which is bad.
But hey, some Microsoft automatic upgrades, teared down thousands of servers , not booting anymore , which is more than bad.
And kernel & base of FreeBSD where not affected. Installed ports where not affected.
- 1) Maybe pkg should do more checks on it's incoming data
- 2) Checks on it's storage.
- 3) Pushing databases on the servers should be verified.
But this is only my wild gues

)