pkg from only trusted sources keeps being trusted