Are companies that are compromised by supply chain attacks held responsible for their negligent behavior?
Blindly pulling updates from providers that offer you no contractual guarantees has to be gross negligence right?