Just in the venv for the app that scans the dependency tree for #zizmor flaws, there are 88 repos that I'd need to file Pull Request to fix my supply chain. This is going to take years.
(this runs zizmor against every repo for every dependency to find out who is likely to turn into a malicious artifact next)