Term Kind Topic What it is
Artifact Signing practice Supply Chain Security Cryptographically signing build outputs so that deployment can verify what is being run was produced by the expected pipeline from the expected source.
Build Provenance Attestation, SLSA Provenance, Artefact Lineage pattern Supply Chain Security A signed, verifiable record of which source, builder and inputs produced a given artefact, checked at deployment - which makes the integrity of the build system testable rather than assumed.
Build Provenance Artefact Attestation, SLSA Provenance practice Supply Chain Security A signed, verifiable statement of what was built, from which source, by which builder, with which dependencies - so a consumer can check that an artefact corresponds to reviewed source.
CI Secret Exposure Surface Build Credential Blast Radius, Runner Secret Surface concept Supply Chain Security The set of credentials reachable by any code that executes in a build job, which is usually far larger than the job needs and is exposed in full by a single compromised step.
Dependency Confusion Internal Package Name Hijack, Registry Resolution Confusion concept Supply Chain Security A build resolving an internal package name from a public registry because the package manager prefers the highest version across all configured sources - an anti-pattern in resolution configuration rather than…
Equifax 2017: A Known Patch and an Expired Certificate Equifax Breach case-study Supply Chain Security An unpatched framework vulnerability provided entry, and an expired certificate on a monitoring device meant the exfiltration went undetected for months.
Reachability Triage Exploitability Prioritisation, Vulnerability Relevance practice Supply Chain Security Prioritising dependency vulnerabilities by whether the vulnerable code path is actually reachable and exploitable in your application, rather than by severity score - which is what makes vulnerability manageme…
Software Bill of Materials SBOM tool Supply Chain Security A machine-readable inventory of every component and dependency in a piece of software, including transitive ones, used to answer exposure questions quickly.
Supply Chain Attestation SLSA, Provenance Attestation practice Supply Chain Security A signed statement about how an artifact was produced — from which source, by which builder, with which inputs — verified before deployment.