We could just:
1. Set up one unified package repository common to all distros. Or say Debian alone.
2. Set up an audit pipeline of human oversight on every commit going into that repo. Nothing makes it in without a million eyeballs scouring it.
3. If it's a distro-independent repo, developers from all distros join the audit process. All eyes like lasers on one pipeline.
4. Set up proper crypto signatures for each distro. Doing so per package complicates it a bit.
#Linux #ESR