> I don't know how Google's or AOSP's build systems are set up, but I'd suspect that not many entities are able to mount a successful supply chain attack on internal networks.
This classic article might be worth your while:
https://medium.com/@alex.birsan/dependency-confusion-4a5d60f...