This is the difference between a distribution and a simple package manager. Linux distributions have a more holistic approach to this and enforce it with checksums, signatures, reproducible builds, etc. A package manager really only cares about managing the packages installation, dependencies, etc. Not the integrity of the packages themselves.