@Lyude What is this supposed to mean?
Imho, from the point of view of "supply chain attacks", using an open source or a closed source dependency can still expose to the same issues (how do you ensure a release is legitimate, that no one inserted malicious code in your download (source or binary)?)
More importantly, if your business relies on open source project dependencies, you should probably invest some money to ensure those projects are well maintained. (Give $ to open source devs !!!).