minimum-release-age
I wonder if this is not in part the same situation as we arguably had with the xz compromise: some imminent change would have made the attack harder (in xz's case, IIRC a change to systemd to dlopen the compression library instead of directly depending on it), and the attacker rushed before the opportunity window closed.
Granted some human will likely have to review it. Or packages flagged by Al could require users to explicitly allowlist them.