> Then the obvious question is: Why? Why use pickle? The most likely answer is “because <X> can’t represent what I need to transmit”, but for that to be at all useful to your proposal, you need to show examples that won’t work in well-known safe serializers.
As Open source AI booms, the risk of supply chain attacks also increases.
You could also use joblib format as well.
Nice article but I can see your point.