

not only do you have to setup the infrastructure to host multiple repositories (deb, rpm), you also have to build and deploy multiple packages of sufficient quality that you don’t break something else, which for a common/popular package would make the malware immediately noticeable.



I personally recommend Fedora KDE. It’s polished and set up reasonably for the average person so you should never need to even open the terminal (you might need to fiddle with some stuff like enabling flatpacks but thats all sone in a GUI application), and it’s reasonably up to date withour shipping broken packages.