I've seen this firsthand...I think it is less of an issue at smaller companies where taking initiative and leaning into their intelligence is less politically restricted. At large organizations, often it requires too much energy for them navigate the bureaucracy and tap into their potential.
Now developers just need to make sure they secure their code at the pipeline level. Pipeline compromise = package compromise.