code becomes trusted by review, but these crowd sourcing efforts to do so fizzled out, so in practice we have weak proxies like number of downloads
the implicit trust we have in maintainers is easily faked as we see