As a maintainer of OpenSource libraries and packages, there is something that kept feeling off in the whole Software Supply Chain discourse. I think this comes down to something simple.
I am not a Supplier.
You can read more explanation there https://www.softwaremaxims.com/blog/not-a-supplier