On what basis can you say that? It’s clear that a corporation that accepts legal liability for the software they run in production or ship would have a strong incentive to create a process around determining the origin of said software.
It's true that different open source projects care about different things (and some may genuinely not care about who contributes), but there are plenty of prominent open source software projects (the linux kernel, various programming languages, apache, etc) who deal with people who would like to submit vulnerabilities or simply cannot code well enough to avoid problems. It seems like all projects would like to avoid those outcomes, even if their legal situation is different, and providing a verifiable certificate chain could be a method of achieving that (either in contributions or in distribution).
Strong incentive no. In fact, most volunteer open source developers release their software with no legal liability at all (cf. MIT license).
For example - even though the GPL contains, to the extent legally possible, an "as-is" clause like the MIT liscence, it's extremely common for GPL projects to publish information (ex: hashes, known good package repos, etc) that help people ensure they've gotten the software they expect. Sigstore seems like it's driving towards the same goal.