upvote
I’ve always thought there should be a module-level safety property in the type system such that unsafe would be a capability granted by the user’s code.
reply