The solution is called curated package feed. Using private one instead of default public package source, you get a trusted source. All updates should be done by first pulling the new packages to the private feed and only after passing the reviews - update.
A little bit of bureaucracy in form of best security practices helps with supply chain attacks.