Golang at least gives you the option to easily vendor-ize packages to your local repository. Given what has happened here, maybe we should start doing this more!
The problem comes when you want to upgrade your dependencies. How do you know that they are trustworthy on first use?