Are you not concerned with the software developers doing something outright malicious in the software itself?
In the end, at some point you either have to inspect every line of code yourself or trust others to have done it for you. Package managers fall into the latter category.