Straw Poll
Do you trust packages you download from package repositories such as npm, PIP, Nuget etc?
CocoaPods, cargo, gems, PIP, npm, NuGet, Conan. There's a package repository for everyone these days.
