Without the ability in WordPress to easily specify an alternative plugin repository for automated updates, Matt Mullenweg is basically a living supply chain vulnerability in the WordPress ecosystem.
Put another way: if Matt & #Automattic turning off #WPEngine access to WordPress dot org demonstrates anything, it's that #WordPress has a fundamental supply-chain vuln in the form of its total reliance on WordPress dot org for automatic updates. & in Matt's autocratic control of the platform.