Unless the entity that pushes the updates become malicious, then they're a security hole.
Clearly more eyes are good, but... In between “Wild West WebExtensions” and “Mozilla backdoors my Firefox and it gets used for nefarious purposes” and “delays in browser updates increase exploitation windows”, I know which threat models I’m buying.
Then, even if developers keys and computers are compromised, I would notice something is wrong.
* No, of course that I don't always do that. I even don't often do that. But I did do that in the past, and I'd like to have the option to do that.