@cj well said. Very complex problem. Even the most stripped down os is going to have some core building blocks that can result in a supply chain compromise. Not really sure there is an answer much less a single answer.
Much of open source depends on trusting contributors and this was such a subtle campaign to gain trust, with a sock puppet campaign to pressure the maintainer who is just a volunteer