Hex 2.5 is focused on making it harder for a malicious or compromised release to reach your system. Supply chain attacks on package registries have become routine, and the pattern is familiar across every ecosystem. An attacker compromises a maintainer account or a build pipeline, publishes a tampered release, and automated tooling pulls it into thousands of projects within hours, long before anyone notices.