The counterpoint would be the Debian-specific loss of private key entropy [1] back in 2008. While this is now a very ancient bug, the obvious follow-up question would be: how does Debian prevent or mitigate such incidents today? Was there any later (non-security, of course) incident of similar nature? [1] https://en.wikipedia.org/wiki/OpenSSL#Predictable_private_ke...
Debian does a lot of patching that is not strictly required for distribution reasons. Here are the GnuPG patches for example: * https://udd.debian.org/patches.cgi?src=gnupg2&version=2.4.7-... There is a lot of political stuff in there related to standards. For a specific example see: * https://sources.debian.org/src/gnupg2/2.4.7-19/debian/patche... The upstream GnuPG project (and the standards faction they belong to)…
To be fair, in Debian's case politics come with the territory. Debian is a vision of what an OS should be like. With policies, standards & guidelines aimed at that, treating the OS as a whole.
That goes well beyond "gather packages, glue together & upload".
Same goes for other distributions I suppose (some more, some less).