Project I'd love to see:
A cross-distro collab to track ensloppified upstreams, last-trusted versions of them, and sets of backported security & general important bugfix patches.
Divided this might seem untractable, but working together, I think it's very practical to render the compromised upstreams irrelevant.
