Earlier quoted context omitted.
Linux package managers are not trustworthy. That is another case where everyone pretends that it is. Usually packages are created and updated by random people and can be pseudonymous.
Oh crud, you are right. Any idea how to fix this? Perhaps a more curated (and more manageable) list? That would seem to be in conflict with our bazaar model.
Of course, you can always find something wrong with every approach, but the truth that everyone needs to face here is that you need to trust SOMEONE to distribute good software to you.