As long as you stick to the official repositories you're trusting the people Canonical trusts to do their packaging and the upstream software authors not to sneak backdoors into their software. Whether that's good enough for you can only be answered by you.