Vendor vetting is a snapshot, not an answer
"We vetted our vendors" was never the answer. It's a snapshot of one moment, taken before a breach that was always going to happen.
Last week, Bitwarden's CLI was compromised. For 90 minutes, anyone running npm install @bitwarden/cli got a credential-stealing payload. The attackers got in through a compromised Checkmarx GitHub Action that Bitwarden used in their build pipeline.
Bitwarden's customers got hit not because Bitwarden was careless, but because something broke down a chain they had no visibility into.
If your takeaway is that you need to audit your vendors' vendors, you're learning the wrong lesson.
Nobody thinks of a GitHub Action as a vendor. And even if you did, what would you have told Bitwarden? Stop using security scanning in your pipeline? The thing they added to make their build safer became the attack vector.
The signal existed. Checkmarx disclosed their compromise. In a future where every vendor's security posture is wired into automated controls across the ecosystem, you could imagine a hold getting placed on Bitwarden the moment Checkmarx went public. That world doesn't exist yet. Today the gap between "Checkmarx had an incident" and "a Bitwarden package will be malicious for 90 minutes on Tuesday" is uncrossable.
Worse, the malicious package was published with valid provenance through legitimate credentials. The supply chain controls that do exist wouldn't have caught it.
The right question is: when your vendor gets breached, what happens to you? Do you know what they have access to? Would you detect it quickly? Could you respond at the speed the attack moves?
One compromised dev tool propagates across every repo, every pipeline, every machine it touches. The blast radius is everything that token can reach.
Assume breach. Limit blast radius.
Keep vendors to the minimum access needed. Treat every package as potentially hostile. Move toward runtime dependency monitoring instead of quarterly audits.
The question shifts from "how far down the chain are you watching?" to "how much damage can they do when they get in?"