In view of the progressing amount of supply chain attacks (and other attacks...), I would like to know your risk assessments and protection measures.
HeidiSQL has an auto updater, which prompts the user when an update is available. Such an updater was recently attacked for Notepad++, see their website: notepad-plus-plus.org, path /news/hijacked-incident-info-update/ (I'm not allowed to post links apparently.)
What's the status for HeidiSQL updater?
What about web site, download links and download assets protection?
What about risks of hacked dependencies getting included in the builds?
Any other risks worth considering?