Hacker News new | ask | show | jobs
by bamboozled 444 days ago
Not a lot in most cases. You’re still just grabbing a package and blindly building whatever source code you get from the web. Unless the maintainer is doing their due diligence nothing.

Goes the same for almost all packages in all distros though.

I’d say most of us have some connection to what we’re packaging but there are plenty of hastily approved and merged “bump to version x” commits happening.