The Muggles Guide to Software Supply Chain Security
Software supply chain security is rapidly gaining attention, thanks to major vulnerabilities like dependency confusion, as well as software supply chain attacks against critical and pervasively used tools like SolarWinds and Codecov. In particular, open source software has faced the brunt of the attackers, forcing the industry to increase efforts in securing the software supply chain.
In this series of blog posts, I cover software supply chain security - what it is, how it is different from the traditional software development life cycle, and various industry efforts to improve trust and integrity of the software supply chain.