How are the alternatives any better? Download a DEB that executes arbitrary code, signed with some .asc that's sitting in the same webserver? Download an EXE?
Your comment is so rambley that I can't understand whether you're criticizing the distribution method or the packaging. Both of those are very different in terms of attack surface, if you're talking about supply chain attacks.
yeah, but it'll be hard to make those Y Combinator vultures rich at that price