This is a flaw with the repository model for software distribution: it confers the authority of the OS developers to packages not scrutinized to the same degree.
Users' metal models of trustworthiness don't track very well the actual scrutiny software is subjected to. This might be a problem with any distribution system.