Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
6 to work through
-
advanced
A critical CVE is announced in a widely-used library. Walk me through the first four hours.
2 min answer -
advanced
A data-protection platform depends on hundreds of third-party libraries. What controls meaningfully reduce supply chain risk, and which are theatre?
2 min answer -
advanced
A developer tools company distributes software used inside thousands of organisations. What supply chain controls matter most, and why is this threat model different from a typical SaaS?
2 min answer -
advanced
An organisation wants to reduce software supply-chain risk. What actually reduces it, in what order, and which popular measures provide less than they appear to?
3 min answer -
advanced
Codecov disclosed in 2021 that its Bash Uploader script had been modified to exfiltrate continuous integration environment variables, that the modification had been live since late January and that it was found on 1 April by a customer comparing checksums. What made this compromise so productive for the attacker, and what would have limited it?
3 min answer -
advanced Multiple choice
Your pipeline signs every container image. Is your supply chain secure?
2 min answer
9 terms in this topic
Artifact Signing
Cryptographically signing build outputs so that deployment can verify what is being run was produced by the expected pipeline from the expected source.
patternBuild Provenance
A signed, verifiable record of which source, builder and inputs produced a given artefact, checked at deployment - which makes the integrity of the b…
practiceBuild Provenance
A signed, verifiable statement of what was built, from which source, by which builder, with which dependencies - so a consumer can check that an arte…
conceptCI Secret Exposure Surface
The set of credentials reachable by any code that executes in a build job, which is usually far larger than the job needs and is exposed in full by a…
conceptDependency Confusion
A build resolving an internal package name from a public registry because the package manager prefers the highest version across all configured sourc…
case-studyEquifax 2017: A Known Patch and an Expired Certificate
An unpatched framework vulnerability provided entry, and an expired certificate on a monitoring device meant the exfiltration went undetected for months.
practiceReachability Triage
Prioritising dependency vulnerabilities by whether the vulnerable code path is actually reachable and exploitable in your application, rather than by…
toolSoftware Bill of Materials
A machine-readable inventory of every component and dependency in a piece of software, including transitive ones, used to answer exposure questions q…
practiceSupply Chain Attestation
A signed statement about how an artifact was produced — from which source, by which builder, with which inputs — verified before deployment.
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.