1) It's worth noting that the SolarWinds build environment was compromised months before the effects of it were discovered. (This is painfully consistent)
1/12
2) Instead of the attackers modifying the SolarWinds source code, they modified the build environment to insert their back door. This may be a nod to the classic "Reflections on Trusting Trust" paper¹, but is more likely because it's stealthier.