Enough time has passed that I feel like I can share my (possibly controversial) perspective on software supply chain security without it seeming reactive or opportunistic:

@kyle Good article but bootstrapping wasn't mentioned. The Guix developers have made good progress on this:

