Looks like there's a pretty decent level of security review for packages going into SUSE's rolling distro:
oss-security - Mozilla VPN: CVE-2023-4104: Privileged vpndaemon on Linux wrongly
and incompletely implements Polkit authentication