It's all about securing the software supply chain. Mark Russinovich had a keynote on the general topic at RSA 2020, especially the section on package managers from 0:29 onwards: https://www.rsaconference.com/industry-topics/presentation/c...
Can anyone point to a technology company that has a larger attack surface or a more fundamentally insecure product?