i hate it when my fedi instance goes down because the domain name got revoked by the FUCKING TALIBAN
.dev is owned by google, which isn't this kind of bad, but a surprising amount of open source stuff is pinned there
domain attacks make for really good home user supply chain attacks, because many install scripts you're told to invoke to init things pull scripts from a bare URL now. you probably wouldn't notice that your zi or fleek (the two that most come to mind) init target has been replaced and added some malicious stuff to the script.
which is a big reason to clone the repo and pull your scripts from there instead, if nothing else. (DYK topgrade.rs will pull your un-local-changed repos when you run a system update with it? you don't need to remember to.)
