Is it even possible to fully secure the supply chain?
Introducing any outside code or hardware is a liability. Unless there is a really urgent problem, I think they should just freeze their entire computer platform, that way they can eliminate any chance of any new threats.
I can not possibly imagine any cost justification for doing so. I have no problem with taxpayer money being spent to keep ancient computers running forever. Keeping our nuclear missiles secure is priceless.
What new features do they even need that they don't have now?
The thought of some ux monkey using npm anywhere near our ICBMs makes my physically ill.