You're welcome.
>It's just that in order to keep my system safe I don't go around installing
anything just because some website says me "trust me, install this and dive
in!"
This is a very sound policy. I think things from the repo are inherently
safer.
The whole situation with the certificates is so very broken. We both browse
the web with a browser that contains certificates from e.g. TÜRKTRUST
(Turkish Military Force Solidarity Foundation), Comodo, CNNIC (China Internet
Network Information Center), Intel, Baltimore, Japanese government,
Microsoft, Staat der Nederlanden (Netherlands) and two dozen other CAs.
https://en.wikipedia.org/wiki/Certificate_authority#CA_compromise