Earlier quoted context omitted.
For SC security, the fewer points of attack between me and the source the better. For other kinds of quality, I have my own tests which are much more relevant to my use cases than whatever the distro maintainers are doing. I've been a DD and while distros do work to integrate disparate upstreams as well as possible, they rarely reject packages for being fundamentally low quality or make significant quality judgements…
I have seen scenarios where package maintainers have rejected updating packages because the upstream is compromised though.
In the end most distros will be saved by the fact they don't upgrade quickly. Which is also accomplished by MVS without putting another attack vector in the pipeline.