I mean I don't see how it's any different with app stores or any app. any developer could install any backdoor at any time with any packaging/update mechanism in any os or app delivery mechanism.
if anything this is the most transparent since the update notes are signed by a release key and there a...