Our startup is working on this problem, initially for the javascript ecosystem. We’re offering insurance against vulnerabilities in javascript dependencies: https://bitauth.com/
We have open source developer tooling for signing and verifying signatures of javascript packages, and we’re offering security as a service, backed by up to $1M in insurance coverage.
We’re still in beta, but we’d love feedback from HN!