Project I'd love to see:

A cross-distro collab to track ensloppified upstreams, last-trusted versions of them, and sets of backported security & general important bugfix patches.

Divided this might seem untractable, but working together, I think it's very practical to render the compromised upstreams irrelevant.

@dalias what about projects where security patches and bugfixes being back ported are also slop
@skatecloud I used the word backport loosely. If that's the case someone needs to understand the issue and write a correct patch.