One would hope. Yet, SCM security is so lax and such an afterthought that Wheeler had to write a whole piece on it:
http://www.dwheeler.com/essays/scm-security.html
After all that, only one OSS project responded with claims to meet many of the requirements. I figure the commercial situation isn't much better with most "benefits" existing on paper rather than with strong security.
To top it off, anyone defending against nation-states must remember they always attack what's below and around the software. Possessing 0-days in OS or management software should let them bypass build-system security to insert stuff in. I'd say OpenBSD, memory-safe implementation, and highly-assured guard for protocol-level at a minimum if better stuff wasn't available.