You should check the source code for every project you're using as much as possible to really ensure that there isn't anything obviously nefarious like telemetry included, because in some cases it's still there.
See Sunxi's Linux SBC backdoors on git for one of many examples of undocumented insecure or privacy-breaking code. In other cases it may be more documented, such as Golangs baked-in telemetry.
There should be better ways to check these problems. The best I have found so far is Crev https://github.com/crev-dev/crev/. It's most used implementation is Cargo-crev https://github.com/crev-dev/cargo-crev, but hopefully it will become more required to use these types of tools. Certainty and metrics about how many eyes have been on a particular script, and what expertise they have would be a huge win for software.