https://www.stepsecurity.io/blog/supply-chain-security-alert...
https://semgrep.dev/blog/2025/security-alert-nx-compromised-...
"It's dangerous to just deploy code that you didn't write and you haven't verified!"
....