Supply chain security has moved closer to the humans with hands on the keyboard.For years, security teams have treated production systems, CI/CD pipelines, and identity infrastructure as the most sensitive parts of the software lifecycle. That is not wrong, but it is incomplete.