Recently, President Biden put out an executive order that mandates that NIST et al work out, over the next year, an SBOM/supply chain mandate for software used by Federal departments.
That's going to require the equivalent of "chain of custody" attestations along the entire build chain.
Along with SOC and PCI/DSS and other standards, this is going to require companies and developers to adopt NixOS type immutable environments.