How do you imagine that protects you? If anything I'm inclined to trust the LineageOS supply chain more than the OEM on account of being a smaller target, having less bloat, and being 100% open from start to finish.
For a particularly sensitive context I'd want to build the ROM myself on an appropriately secured machine running one of the major distros.
Financial apps like banking ones sometimes refuse to work on rooted phones and you have to follow if you want to run them.
I just have no time and knowledge to build ROM myself. 100% open projects also suffer supply chain attacks.