There is or was a project called WinApps i think that made it easy to set up a VM to run some applications.
progandy
Porteus kiosk thin client might be an option.
Nod32 offers a commercial antivirus for that scenario as well. The consumer variant has been discontinued.
That depends on the depth of the review, e.g. verifying the submitter is a member of the project, the software name does not conflict with a well known name,...
At least this prevents impersonation of well-known publishers or their software. Maybe all changes to metadata like the description should require a manual review even for established packages.
Those getting the most recent software versions, so nothing that should be running in a server.
I think that was a precaution. The malicious build script ran during the build, but the backdoor itself was most likely not included in the resuling package as it checked for specific packaging systems.
There is an actively maintained project for github: https://github.com/josegonzalez/python-github-backup
In that case you should ignore the interface in networkmanager (set it as unmanaged) and add one of the wireguard gnome shell extensions i think. https://extensions.gnome.org/extension/3612/wireguard-indicator/
That is regrettably not too unusual. Many platforms deactivate / ban empty accounts that were inactive for a long time. I guess "aging" accounts before use is something not too uncommon for bots.
With usb-c you should be able to load a driver that allows network connectivity regardless of otg mode. Or was it Thunderbolt?
Update: I thought of thunderbolt-net which works with Thunderbolt 3 and probably USB4