I’m more concerned about OpenBSD. Given how centralized the project governance is, and its base in Canada, I can imagine the government attempting to (for example) force the project to serve backdoored images or updates to targeted people. A backdoor or bugdoor in the source would probably be spotted by someone, and I’m not even sure the bill allows a broad tool like that, but that’s not the only way to compromise software users.
Fortunately the mirrors are distributed, so maybe that reduces the risk.