bingo
... from a longer transcript here https://www.infoq.com/presentations/security-supply-chain-os...