The CA in question is CN = Sectigo RSA Code Signing CA
https://sectigo.com/resource-library/comodo-ca-is-now-sectig...
From the view of the certificate holder, the CA has one job: Keep their certificate valid. Everything else (including the trustworthiness of the CA, e.g. whether they issue false certificates) only matters insofar as it affects that job (if the CA were to screw up up badly enough to get removed from certificate stores, the certificate also becomes invalid, but other than that, the certificate holder doesn't really care how the CA acts).
By relying on a CA known to take such action (whether justified or unjustified), you're putting the continued usability of your software at risk, i.e. there is a strong reason to pick any other trusted CA.