@debacle No. I thought until recently that usepackage only installs released packages on ELPA, MELPA etc. so that I installed unreleased packages with straight that uses github directly. I only now learned that use-package can do this without straight. I know the brilliant package from Jason Ross for quite a while, which exports from org to context, which makes my writing workflow complete.

#security is always an issue but emacs seems to me quite robust in this regard. It's not npm. ;-)