Just taking a guess: supply chain attacks may occur the same (or even more) but they’re less impactful client side. Makes it easier to have more trusted server-side code and less validated client-side JS.
That was my assertion, I said the surface for attack included supply chain. As another poster pointers out, that is in fact reduced under some circumstances, since the runtime context is browser side.