This seems like critical prerequisite infrastructure, which is fantastic — although not yet what I was asking for. As far as I can tell there is not yet a way for individual WordPress installations to actually benefit. However, it seems that work is underway: https://gossamer.tools/project/wordpress
> The intention was to allow security vendors to offer code reviews of open source dependencies
What I care most about is just quorum publishing where multiple independent identities sign a release, so that an attacker has to compromise multiple trusted identities to execute a supply chain attack. I'm not too excited about reviews beyond that. The main thing is to upgrade collective ecosystem security by hardening automatic updates.