> It’s about as non-approved as ad hoc shell scripts.
That's not a fair comparison. There's a big difference between your own ad hoc shell script (or command line or whatever) that you fully understand, and downloading and running third party code without any kind of audit.
Meanwhile, the industry keeps talking about "software supply chain".