Conversation

Replying to and
Most Linux distributions fully trust the packagers and a central build / signing server, along with not verifying signatures for sources. I think you're unfamiliar with how it works elsewhere if you think trusting 20 vetted people to sign builds of packages is bad.
2
Having a central build / signing server doesn't mean a developer wasn't also fully trusted with what they told the server to build, without anyone reviewing what they asked it to build. It's usually not the case that a central build server is trusted *instead* of developers.
2
Replying to and
I don't know what else to say beyond that I didn't say that. I don't understand why you're mad at me. I've been trying my best to clarify what I said initially and I wasn't trying to turn it into something hostile.
1