Supply Chain Security Standard
Supply chain security protects the integrity of third-party dependencies and build pipelines.
Defenses
- Trusted Registries Only: Package ingestion restricted to verified, trusted registries.
- Provenance Verification: Package names, namespaces, and publisher signatures verified against typosquatting.
- Automated SBOM: Software Bill of Materials generated and published with every release.