what the fuck
what the fuck
Reminds me of that HN comment I saw where some US company started a rewrite of their frontend when they discovered that the 100% FOSS UI components library they had been using was developed by a Chinese company. Cut off your nose to spite your face and all that.
Wait until they learn how much code of Chinese and Russian origin there is in the Linux kernel.
Hardly anyone walls off their on-prem/on-cloud CI services, the amount of damage that a dedicated and actually skilled actor can do before being stopped is immense - we're lucky that most of the malware in the NPM ecosystem has been credential stealers (which were then used to mine cryptocoins) and cryptocoin miners, so relatively harmless in comparison to what an attacker might do in a war.
Don't forget how Russia killed off a bunch of windmill remote management systems as they executed a hack on a sat-internet provider early in the Ukraine war. No one is safe from being collateral damage.