Software supply chain attacks
An attack on the software build pipeline can to some degree be compared to an attack on your supply chain. Your code can be 100% reviewed, but still the end product will contain malicious code – a very dangerous situation.
Defending software build pipelines from malicious attack – NCSC.GOV.UK