Software Supply Chain Security
Enhancing software supply chain security is a priority issue for the open-source community. Recent exploitations such as CodeCov, SolarWind, Accellion and few others have damaged the business financially and loss of trust.
Here I would like to start by sharing findings from 8th Annual Report on State of the Software Supply Chain by Sonatype.
After careful analysis of findings from this report, this article reflects on the good practices that create ideal outcomes, and likewise, the poor practices that produce problems. As always, the goal of this article and subsequent is to provoke practices at developer level that improve software supply chain security and create fulfilling work experiences based on followings:
Let us understand it one by one:
Open-source Supply, Demand and Security
The supply of open source continues to grow at an impressive rate. The expansion of the overall volume available combined with the increase in consumption means threats also continue to expand in scope, impact, and volume.
As per the report software supply chain attacks increased another 633% YoY, averaging a 742% average annual increase in software supply chain attacks over the past three years.
领英推荐
Now let us have a look on some of key tactics used in software supply chain attacks.
Lessons learned from Log4Shell
Thanks for reading this article, in subsequent post I will focus on other attributes for software supply chain security.
Please share your feedback and suggestion in comment box. Do like and share with others if you find this work interesting.
Arunkumar VR Anish T S Priyamvadha Vembar Prakash Ramasamy Sureshkumar VS Tamilselvan Sellappan Harishankar VS Major Satish Bhatt Dr. K Rajesh Rao Lakshmi Prathyusha Vedantam
Nihal P. #bgsw #softwaresupplychain #softwaresupplychainsecurity #devsecops #opensourcesoftware #cybersecurity #cybersecurityawareness #cybersecuritytips
Gen AI Expert |AI in Cyber Security |Cloud Security | Cyber Security
1 年In last 3 years there is huge increase is software Supply Chain attack. As per report published by Sonatype " software supply chain attacks increased another 633% YoY, averaging a 742% average annual increase in software supply chain attacks over the past three years." Its time for Security Architects and security practitioners to pay attention of transitive dependencies and secure software supply chain. l