Supply chain security is the practice of protecting the integrity, provenance, and trustworthiness of the components, dependencies, and processes that compose a product, with particular emphasis on software supply chains. It addresses threats such as compromised dependencies, malicious build tooling, and tampered artefacts through measures like signed releases, software bills of materials, and reproducible builds. It has become a critical discipline as systems increasingly assemble third-party code and hardware.

Content

  • Software supply chain controls include cryptographic signing of releases, software bills of materials (SBOMs), dependency pinning, provenance attestations such as SLSA, and reproducible builds that let third parties verify artefacts. Hardware supply chains add concerns of counterfeit parts and implanted firmware. Because a single compromised upstream dependency can propagate to thousands of downstream systems, supply chain security has shifted from a niche concern to a board-level priority following high-profile build-system attacks.