Earlier quoted context omitted.
Go’s package repository is just GitHub. At the end of the day, it’s all a URL. You’re asking for a blessed set of URLs. You’d have to convince someone to spend time maintaining that.
Golang at least gives you the option to easily vendor-ize packages to your local repository. Given what has happened here, maybe we should start doing this more!
The problem comes when you want to upgrade your dependencies. How do you know that they are trustworthy on first use?