In their current drive for innovation and cloud migration, organizations increasingly rely on software development and all its dependencies: third-party code, open source libraries and shared repositories. Recent attacks have shown how easy it is to create confusion and send malicious code undetected through automated channels to waiting recipients. State-sponsored threat actors have engaged in software supply chain attacks for longer than most people realize, as governments seek out access to information and potential control. SolarWinds delivered a hard truth to defenders: everyone is vulnerable when trust can be abused. While Russian APTs have garnered much attention, Chinese APTs have been the force behind more attacks than people may realize, targeting the technology sector for economic espionage and intellectual property theft. As we innovate our enterprises line by line, adversaries are finding their strength in our weaknesses and vulnerability in our dependencies. Are we ready for what else comes down the CI/CD pipeline?