I don't think Arch maintainers are responsible for auditing upstream. They package the upstream only.