/oss/en/openforge/standards/supply-chain

Supply Chain Security Standard

Dependency governance, package identity verification, and registry defense.

Supply Chain Security Standard

Supply chain security protects the integrity of third-party dependencies and build pipelines.

Defenses

  • Trusted Registries Only: Package ingestion restricted to verified, trusted registries.
  • Provenance Verification: Package names, namespaces, and publisher signatures verified against typosquatting.
  • Automated SBOM: Software Bill of Materials generated and published with every release.

Canonical Source