We also see what seems like rather balkanized approaches (npm, pypi, cargo, ...). It would be great if broader consensus arose on what the ideal standard should be for package management and distribution that then those projects could adhere to. Similar about commit access to repos and what the requirements there should be.
It's also peculiar how much stronger the guarantees you get from your operating system vendor are w.r.t. signatures on packages vs what the underlying projects themselves have. OSs have had this pretty well handled for decades, but no common best practices like 2fa, signatures, etc seem to have emerged.