honestly it is for #gossiplistener I figure with the rapid development, it would be easier/better to update a single file and have the scripts deploy.
so not strictly supply chain concerns, but will help with that
in the past i would use JenkinsCI for this, but I do not have one running locally.
That said, it would have been a much quicker process to use Jenkins for this...not sure it would be better though.