Godot definitely has sponsors which while not directly being “customers” are still very important when it comes to financing the development of the engine
Having said that I want to believe current sponsors won’t have issues with the Godot Foundation here
Python with PyPI, C# with Nuget, Docker with Dockerhub, Java with Maven Central, hell even just regular Linux packages from dodgy repositories…
Supply chain attacks concern almost everything everyone everywhere.