Trust mechanisms in GitHub/etc can’t solve the whole problem, for sure.
But some automated safety mechanisms at scale can reduce the risk for those who don’t follow perfect security practices, which has value to the world at large.
Very few of us have the capacity to do even cursory validation for every update to every dependency of every bit of software we use.
The main benefit of reusing software packages is that you don’t want to spend the effort of writing/reviewing all the internals of the component.
At some point, to trust an abstraction blindly, you need to instead follow reputation. Who has authority to say what is reputable or not is the difficult dilemma.
As seen with CVE authorities lately, it’s not easy. As much as they undermine their own authority by declaring everything as a CVE, vice versa, declaring every org in GitHub as “Verified” may eventually be easy for scammers to get as well.
Back in the days, just having an SSL certificate on your web site was a big stamp of trust. Now everybody has it and it doesn’t mean anything.