Compromising the open-source supply chain is easy to do and spreads more quickly than traditional supply-chain attacks, ...