A Crash Course in Software Supply Chain Security
- View all articles
Zachary Newman
Former Principal Research Scientist
Chainguard
Zachary Newman Former Principal Research Scientist
Software supply chain security is an enormous problem: it covers everything from build systems to the code in open-source dependencies to package managers to social relationships between developers.
Unfortunately, we know about hundreds of supply chain compromises, and there are likely just as many that were never discovered or reported. All told, it's a pretty daunting task to sit down and try to understand the field. That's why Chainguard has put together a Software Supply Chain Reading List! This list covers some of the best explanations, analysis, proposals, and data sets in the space. A list like this can never be exhaustive, so we'd love your feedback—did we miss any of your favorites?
We hope you find it useful!
Share this article
Articles connexes
sécuritéThe flood is coming and the pipes were already full
sécuritéAthena spotlight: Black Duck on the importance of flagging zero-days at scale
sécuritéHow financial services companies can modernize their software supply chain
sécuritéProven, not promised: Chainguard Containers achieves SLSA Build Level 3
sécuritéThe keyv and cacheable npm Supply Chain Attack: Inside the Mini Shai-Hulud Campaign
sécuritéWhy AI-assisted attacks made software supply chain security its own category