Has anyone ever done a proper security audit of VLC that is downloaded from the web? I don't trust it, and the fact that their releases on Github don't include binaries makes me trust it even less. Nobody is compiling VLC from source, and they don't provide any sort of provenance from the GH actions pipeline.
All linux distros build VLC from source
This seems utterly pointless to worry about. You're fucked either way if you trust VLC.
Care to elaborate?