How were they spying? Help people learn from this incident.
The CI/CD was on github actions. IDK if there is a standard spy tool there.
This company normally took weeks to respond for any other code related issue. I would describe them as passive aggressively slow.
Maybe they really did review everything spot on and just deliberately slow rolled approval to "manage expectations" on the day to day.