Question for @alpinelinux (and other distros): Is there any tooling in place or proposed to catch and block package version bumps, particularly for important dependencies, that would pull in slop code that might introduce bugs and vulnerabilities? Stuff like checking for commits by known slop agents or presence of known prompt files.
Even if a distro doesn't want to permanently hold these packages back or switch to forks (my preference), it seems like any further version bump now requires detailed review for breakage.