maybe the solution is what linux & co used for many years: have a team of people who vet and package dependencies.