SolarWinds speaks out, and software dev can never be the same again
itwire.com
itwire.com
This seems like a high-labor and error-prone way to detect a possible integrity compromise of your build infrastructure. Maybe they've done this, but what software shops need to do is better control the integrity of their build infrastructure and the confidentiality of their code signing keys.
Ideally, build infrastructure would be immutable (resistant to unauthorized change), burnable (defeats persistence), and auditable (changes need to authorized and logged). The build infrastructure itself would produce auditable artifacts from the build, including hashes of input files, compilers, etc.
Long story short, I wouldn't trust them at all.