The Cybersecurity and Infrastructure Security Agency (CISA) and federal intelligence agencies have released guidance titled Securing the Software Supply Chain for Developers.
https://www.securitymagazine.com/articles/98285-software-supply-chain-security-guidance-for-developers