Between the rapid release of open source software, and modern OSes preloaded with packages, enterprises are vulnerable to attacks they aren’t even aware of.
Ehh....Not really a mechanism for that that I can see. I mean, say that there's demand for that, which I can believe. Do I go to a given distro and buy a "security hardened" version? I don't see how that would work. Is the distro going to refrain from incorporating security fixes into the "non-hardened" free version?
If you have read it, you might have noticed that the theme of the article is a company called Chainguard. Enterprises can pay them and get a secure software supply chain all the way down to the container image. More than that, their container distro is actually free and open-source, anyone can use it for free, it's a one line change in your build script to go from Alpine to Wolfi. Enterprises can also buy a secure OS for bare-metal from Red Hat, SUSE, etc...
This article lacks focus and mixes unrelated security concepts in questionable ways. It ends like just an ad for Wolfi. Don't get me wrong, Wolfi is neat, it's probably deserving of being talked up. But it doesn't solve the supply-chain issues pointed out by the article (it doesn't even try). Supply-chain attacks are currently not a major issue in Linux distributions, and enterprises are already tackling the issue of provenance elsewhere, and the article itself notes that. Dependency management for enterprise software is NOT the responsibility of Linux distros. So what is the point of the article? To me, this article is security mumble jumbo.
Are we suggesting that rich people who get a product for free and use it to forklift more piles of money into their scrooge mcDuck like vault ought to demand more accountability from the people who provided the free forklift.
We need more need to normalize companies stepping up to pay for security development for opensource products they utilize. If companies aren't putting FTEs to cover their risk of using a product or service then they should be held liable for any damages that causes them or their customers. This is for more than FOSS and for more than CVEs but also critical errors that cause delays in business continuity.
The issue is many c suite are just now under standing this and many justice systems seem behind on this.