Usually they would like to install a daemon which checks local packages and all Gemfiles for example. The problem would be in ensuring that the daemon does not misbehave. A solution which gets integrated into a CI/CD pipeline would not have this problem but it would not be able to provide assurance on the integrity of the base system, only the artefact (deliverable).