It’s kind of insane this doesn’t happen in the publish pipeline by default.

[deleted]

This is what serious software distribution platforms do. Developers may think that they are special and they would never install malware, but that's just not the case.