Similar Items: Understanding security challenges in the software supply chain through causal relationships