Leading Open Source Author Calls for Verification over Trust in Software Supply Chains infoq.com