(as a devops/security minded engineer) ...and companies wonder how supply chain attacks are possible