Blockchain consensus only works when there are many more “verifiers” than there are items (blocks) to verify. Good luck with the amount of software updates being published and manual reviews.
Regarding manually reviewing software, it would be very easy to create a malicious majority of verifiers who certify malware, because malicious “verification“ takes much less resources than truthful verification. Rather than verifiers being payed, verifiers would need to themselves pay for the right to verify, in order to throttle malicious “verification”.
But realistically, you need verifiers that you trust in the first place, and if those exist, digital signatures are sufficient.