I've used script blocker modules for many years and consistently only white list a few widely used package repos. This means I notice when a web site I frequent adds a new script source.
This ought to be the default in every common web browser, just as you should have to look at the data sharing "partners" and decide whether they're benign enough for your taste.
This ought to be the default in every common web browser, just as you should have to look at the data sharing "partners" and decide whether they're benign enough for your taste.