I think we're approaching this collective brainstorming all wrong. We're not going to solve the xz problem by throwing pennies at burnt out over worked hobby maintainers or by making them jump through extra bureaucratic hoops in the name of security theater. There's only one reasonable solution here and it's to turn maintaining critical open source projects into REALITY TELEVISION.
So.. You gonna buy a house?