The Debian PHP maintainer, Ondřej Surý, maintains his own repo:
* https://packages.sury.org/php/README.txt
* https://qa.debian.org/developer.php?login=ondrej%40debian.or...
Of course in the years since the PPA system was introduced we've seen a lot of projects push in to reproducible builds which somewhat negates that concern, but there are still a lot of us who would rather not go through that process for every random binary we want to run. Having a third party that we inherently trust because they built the rest of the operating system building the random packages we want has an appeal. Also for the devs/packagers free hosting by the OS vendor is nice too.
And what's even worse, if you install Docker containers you don't build and manage yourself, you're pretty much right there again with "I don't know or trust" as your means of security.
It's a very famous computer science paper, pretty easy to read. Nothing niche or controversial. I'm sure you'll find it interesting.
The fact that you can't achieve the ideal does not mean we should claim defeat.
This makes the cases where you want the full Debian build but with a patch or just stepping the version easy. That's useful when you need to patch a package or can't wait for an upstream security fix.
Too often I see people building upstream packages "by hand" in those cases. The packaging tools are great and any Linux user is greatly helped by taking a few minutes and learning the basics of apt preference files, package selection and source packages.
Never heard that term before, but it does, in fact, seem to describe a lot of Canonical's issues in the past decade.
---
[0]: https://www.freebsd.org/doc/en_US.ISO8859-1/books/faq/misc.h...
I, personally, don't have any examples ready to provide you but I no longer subscribe to any "general discussion" lists.