I think one potential stumbling block with package audits/verification is funding them. Open-source in general has tension with often relying too much on volunteer labor, but auditing seems particularly hard to get done that way (not particularly rewarding, requires a high level of attention)