Principles for Package Repository Security