https://www.evasec.io/blog/eva-discovered-supply-chain-vulnerabities-in-cocoapods 
Discussion
Is this solar winds for apple?
That’s an interesting comp, 2 things come to mind when trying to think of differences:
- no active widespread attack happened that I’m aware of for this (tbd)
- Cocoapods is open source software