The software supply chain is the full set of components, processes, tools and actors involved in producing and delivering software, encompassing source code, third-party and open-source dependencies, build systems, package registries and deployment pipelines. Because modern applications assemble large amounts of external code, the integrity of every link matters for security and reliability. Securing it relies on practices such as software bills of materials, provenance attestation and dependency management.

Overview

  • Modern software is assembled from vast amounts of external and open-source code, so each dependency and build step is a potential point of trust or compromise.
  • High-profile supply-chain attacks have driven adoption of provenance, signing and inventory practices.
  • It connects development, build and deployment with security and governance concerns.

Key aspects

  • Source code and first-party components.
  • Third-party and open-source dependencies and their transitive graph.
  • Build systems, package registries and artefact repositories.
  • Deployment pipelines and release channels.
  • Inventories, provenance and signatures establishing trust.

Mechanisms

Applications

  • Securing enterprise build and release pipelines.
  • Regulatory and procurement requirements for component transparency.
  • Open-source consumption governance and risk management.
  • Incident response and rapid impact assessment for new vulnerabilities.

Provenance