this is a small-ish problem with FOSS that doen't have an easy solution. the open source supply chain of code, libraries, tools and apps needs constant peer review, validation and enforcement
i think the tech behind NixOS will go some way to automating this but a coordinated human collaborative effort will be required too
dare i say it even AI might be able to lend a hand