I understand the sanctions part and wanting to head off any potential state interference with projects like this, but “infosec reasons” feels very hand wavy.
I think I’d be a lot more comfortable if we had seen malicious/bad faith actions/communications or maybe some more specific and tangible reasons to suspect them being compromised on the part of the Russian maintainers before they were just removed.
I really like your way of explaining that.
It still feels dirty, but when is war and geopolitics ever actually clean? I feel a lot more heartened that this was the right choice after reading your response.