The problem
The highest-impact supply chain attacks compromise the build environment and the build process. Attacks of this class routinely go undetected for months. Some have run for years. The state of the art does not observe the build itself, which is where these attacks execute. Every incident here passed all of it, CVE-free.

