For end-users, yeah, the package manager is taking care of it. Even though the key layer actually sucks still, at least it's there. But most devs are way too blasé about supply chain security. Especially in js and rust. I cringe every time I see one of those pipe curl to bash oneliners.