Supply Chain Vulnerabilities found and fixed in Fedora's Pagure and openSUSE's Open Build Service
Supply Chain Vulnerabilities found and fixed in Fedora's Pagure and openSUSE's Open Build Service
fenrisk.com
Supply Chain Attacks on Linux distributions - Overview

Governments and enterprises using these distros should be funding them and paying for security audits. They are really dependent on them.
I'm curious what an attack on NixOS would look like. It would be a good candidate for reproducible builds but it doesn't seem like they really care about that.
Anti Commercial-AI license