Let’s take some examples from the post. If a domain is 15 years old and implicitly trusted by this point, then an attacker is just going to compromise an ancient WordPress install to post malware.
If an OSS developer occasionally releases software, attackers might approach them to add a new SDK or monetization opportunity (happened many times to VLC - good thing JBK hasn’t been tempted!), or just straight up attempt to compromise their infrastructure (e.g. download servers, has happened to many pieces of software like Transmission).
If we actually had Let‘s Encrypt for code, attackers would trivially get certs for their stuff. Then end-users would have to decide which certs to trust or not, which would significantly weaken the purpose of code-signing.
Short of just sandboxing all binaries by default, I don’t see a great solution to make binary downloads safe. macOS is already moving very heavily in that direction.