Did you look?
Your question to me is somewhat clear; and you didn't provide a release (thus I've used my own), but looking at the package details can provide some level of security
https://packages.ubuntu.com/mantic/git-lfs
That page along gives me great details, including Original Maintainers are more (beyond just MOTUs)
It tells me it's a community supported package (thus being found in universe
), providing links to the changelog which actually confirm details from the first page I provided (ie. maintained mostly by Debian)
How far in this exploration I'd go will depend on how secure I want to be, which maybe exploring in upstream Debian sid, then to its' source, looking at past changes & how regular they are especially post-changes occurring further upstream etc. etc.
How secure something is is very subjective though, and how far I'll go will depend nervous I am, and how much security matters for my intended usage.