Does the sale require me to submit payment details to a not-already-trusted platform?
The change remotely triggered by Epic redirects users to a third-party (Epic) payment system, but what if it were, say, a malicious Epic insider? How much user payment info/cash could they grab before they were detected and disabled?
"2.3.1 Don’t include any hidden or undocumented features in your app; your app’s functionality should be clear to end-users and App Review."
In old sci-fi books, there's a couple that describe a future where connecting an old device to the Internet without having first installed updates will result in the device being exploited and/or ruined within a few seconds.
I notice that the Xcode worm was reposted again this morning, which seems like the perfect mechanism for covertly preparing for a worldwide hack of all iOS devices through a backdoor that has been compiled into all software. (You could get a similar effect by introducing malware into CocoaPods, and with similar reach.) All of these protections Apple has with Gatekeeper and Notarization would, to many extents, protect end users against that attack.
As you said, it's definitely a broad brush. The risk is absolutely real, though I imagine we all disagree on how important it is. It's the same problem as the risk of Python/Ruby/Node dependency compromises. Any solution that would work for protecting us against an NPM compromise would also work for protecting us against a macOS software compromise. Apple's solutions have a higher total value of protection, in exchange for a higher total value of bothersome.
Is the NPM model (you can ship any code worldwide, have fun!) safe enough for non-technical users, such that Apple could just drop Gatekeeper and let us all go back to the wild west macOS days? If not, what model is acceptable, given that Apple's model isn't?