Supply chain attacks are a thing. Given that we are in an active war with Russia and a trade war with China (which is reasonably expectable to turn into an active war as well), it makes sense to drop everything out of your supply chain where the people with commit and release access are in the reach of these nations' secret services.
Hardly anyone walls off their on-prem/on-cloud CI services, the amount of damage that a dedicated and actually skilled actor can do before being stopped is immense - we're lucky that most of the malware in the NPM ecosystem has been credential stealers (which were then used to mine cryptocoins) and cryptocoin miners, so relatively harmless in comparison to what an attacker might do in a war.
Don't forget how Russia killed off a bunch of windmill remote management systems as they executed a hack on a sat-internet provider early in the Ukraine war. No one is safe from being collateral damage.