In this way Google can (possibly) have a lot of influence on what components
/ libraries / solutions to pick.
Do you want to use our secure packages, which are guaranteed (to some extent) to be safe, or do you feel better using unsecure packages from somewhere else? It is your choice.
I can imagine a lot of enterprise mandating using what Google is providing.
The list of what they already support https://cloud.google.com/assured-open-source-software/docs/s... Is fairly long and that is good, but it ofcourse leaves out a hell of a lot.