I made a list a few years back: https://news.ycombinator.com/item?id=29266992
At the time, I was focusing more on the approach of reducing the number of people you have to trust when you depend on a particular package.