@andrewnez re "Fork networks":
hypothesis: in the current status quo the search for a fork is delayed until it is no longer possible (f.e. due to a security issue or incompatibility with a new major version of another dependency). so people are looking for a fork in a moment of crisis which might lead to insufficient security consideration.
so this feature has the potential to encourage earlier switches (esp. if integrated into dep managers) but it also could be gamed by malicious actors.