Ok? Not sure what a package manager can do about the fact that eventually you want to run the things you install.
Have any kind of provenance. eg like Debian has for 30 years. Key signing in person etc
Have any kind of provenance. eg like Debian has for 30 years. Key signing in person etc