It's unlikely that anyone could really leverage a vulnerability within the Bazzite OS Build updates and sneak something malicious in there...That is the reason why nobody is really talking about it. Some of the measures used are discussed at the link that I put here.
There is always a slim chance of it happening though; I am sure that people understand the reality of supply chain attacks and know when a malicious actor is determined enough, they'd find a way. If this concerns you so much, wouldn't it be wiser to use a distro that doesn't automatically update? One that simply checks for them and allows you to decide if or when you'd like to?
A healthy amount of caution is just right for anything OS related, but, you seem a bit too worried about it.