extremely Clarke & Dawe voice
"So what do you do to protect the software supply chain in cases like this?"
"Well, the repository was moved out of the supply chain."
"Into another supply chain?"
"No no no, it's been moved beyond the supply chain, it's not in the supply chain anymore."
"No, but from one supply chain to another supply chain?"
"No, it's beyond the supply chain, it's not in a supply chain, it's been moved beyond the supply chain."
"Well, what's out there?"
"Nothing's out there!"
"Well, there must be something out there."
"There is nothing out there. All there is is packages, and Git forges, and users."
"And?"
"And a backdoored build of xz."
"And what else?"
"And a CVE."
"And, anything else?"
"And the parts of the servers where the sshd security fell off. But there's nothing else out there."
"GitHub, thanks for joining us."
"It's a complete void!"
"Yeah. We're out of time."
"The supply chain's perfectly safe. We're out of time? Can you checkout this repo?"
"...But didn't you take a fresh clone?"
"Well, yes I did, but..."
"What happened?"
"Well, the sshd security fell off."