> Markdown version of [/videos/468-securing-your-application-software-supply-chain?t=5](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain?t=5). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Securing your application software supply-chain Are you blindly trusting your transitive dependencies? Learn how to systematically lock down your CI/CD pipeline with automated SBOMs and keyless signing before the next SolarWinds-style breach. - **Speakers:** [Niels Tanis](https://www.wearedevelopers.com/@niels-tanis) - **Event:** World Congress 2022 - **Published:** June 15, 2022 - **Duration:** 28:27 - **URL:** https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain ## Summary Modern application delivery has evolved from simple monolithic deployments into complex, fine-grained CI/CD supply chains comparable to physical manufacturing lines. Because a single software application relies on thousands of transient parts, security vulnerabilities have rapidly shifted toward build environments, orchestration protocols, and repositories. Illustrated by incidents like the SolarWinds breach and the Canonical credentials theft, securing this continuous pipeline requires engineering teams to systematically defend every layer of development—from initial source code inputs and IDE infrastructure to third-party library ingestion and final artifact deployment. Securing the initial developer environment begins with mitigating credential sprawl through multi-factor authentication and utilizing Git commit signing to introduce verifiable proof of origin. Since even fundamental development environments like VS Code and their imported third-party libraries introduce extensive transitive dependency trees and unseen contributors, teams must scrutinize the actual intent of imported code. Leveraging evaluation frameworks like OpenSSF Security Scorecards acts as a software nutrition label, empowering developers to assess risk metrics—such as fuzzing density and code review practices—before trusting dependencies, effectively mitigating threat vectors like dependency confusion and orphaned libraries. Moving from code to reliable deployment artifacts necessitates reproducible, deterministic builds that guarantee compiled binaries perfectly reflect their public source code without unauthorized injection. Modern artifact signing ecosystems like Sigstore and Cosign enable keyless, automated container signing via OpenID Connect, integrating seamlessly into workflows like GitHub Actions to bind deployment assets to authorized organizational identities. To formalize pipeline integrity, organizations can adopt Google's Supply-chain Levels for Software Artifacts (SLSA) framework alongside automated SBOM (Software Bill of Materials) generation tools like CycloneDX or Anchore Syft. Generating provenance data is only the first functional step; by actively ingesting these SBOMs into continuous validation pipelines and policy enforcement engines, security teams can algorithmically ensure that only authenticated, untampered artifacts are deployed to production clusters. **Keywords:** software supply chain security, SLSA maturity model, SBOM generation tools, reproducible deterministic builds, keyless artifact signing, sigstore ecosystem, cosign container signing, openssf security scorecards, transitive dependency risks, dependency confusion mitigation, cyclonedx bill of materials, anchore syft container analysis, git commit signing, CI/CD pipeline provenance, deployment policy enforcement ## Chapters 1. **Defining the modern application software supply chain** (00:05) — Transitioning to cloud-native architectures introduces complex development phases that resemble industrial manufacturing processes. 1. **Analyzing the SolarWinds supply chain attack** (04:02) — Attackers compromising build servers to inject malicious code demonstrate the systemic risk of targeted digital infrastructure. 1. **Protecting source code repositories and developer credentials** (05:30) — Implementing multi-factor authentication and git commit signing prevents attackers from pushing unauthorized code via stolen credentials. 1. **Identifying security risks in developer IDE environments** (07:06) — Massive transitive dependency trees in editors create attack vectors like command injection that can arbitrarily alter source files. 1. **Managing risks in third-party software dependencies** (08:46) — Unpatched packages and dependency confusion attacks allow bad actors to exploit trust in external open-source libraries. 1. **Evaluating library intent using security scorecards** (11:11) — Utilizing standardized scoring tools helps engineering teams assess the security hygiene and expected capabilities of external packages. 1. **Generating deterministic and reproducible software builds** (13:20) — Ensuring that source files predictably compile into identical binaries prevents hidden modifications during the continuous integration process. 1. **Securing image deployments with keyless artifact signing** (14:24) — Associating code artifacts with verified corporate identities prevents the execution of untrusted containers in cloud environments. 1. **Tracking components through software bills of materials** (16:40) — Generating granular dependency graphs provides organizations visibility into the exact versions of code running across their infrastructure. 1. **Adopting the SLSA framework for supply chain maturity** (19:27) — Progressively implementing supply chain levels enables teams to automate verifiable provenance without manually juggling cryptographic keys. 1. **Enforcing security policies with verified artifact telemetry** (23:06) — Validating signatures and verifying reproducible pipelines at the deployment boundary blocks tampered releases from reaching production environments. 1. **Integrating security across the application development lifecycle** (25:51) — Adopting a progressive approach to threat modeling supply chains ensures that security practices scale with complex modern workflows. ## Related Moments - [Mapping the complete software supply chain attack surface](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) (from "Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?") - [Introduction to supply chain security principles](https://www.wearedevelopers.com/videos/245-oops-stories-of-supply-chain-shenanigans) (from "Oops! Stories of supply chain shenanigans") - [Understanding software supply chain threats and security risks](https://www.wearedevelopers.com/videos/938-how-your-net-software-supply-chain-is-open-to-attack-and-how-to-fix-it) (from "How your .NET software supply chain is open to attack : and how to fix it") - [Avoiding supply chain risks within standard software dependencies](https://www.wearedevelopers.com/videos/1829-how-to-defend-against-data-manipulation-attacks-bozidar-spirovski-wekoslav-stefanovski) (from "How to Defend Against Data Manipulation Attacks - Bozidar Spirovski & Wekoslav Stefanovski") - [Practical mitigation strategies for modern software supply chains](https://www.wearedevelopers.com/videos/100279-surviving-the-vulnpocalypse-open-source-and-supply-chain-security-in-a-post-mythos-world) (from "Surviving the Vulnpocalypse: Open Source and Supply Chain Security in a Post Mythos World") - [Core principles for implementing DevSecOps in teams](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) (from "DevSecOps: Security in DevOps") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Future of Open Source: A Deep Dive - Scott Chacon at WeAreDevelopers World Congress 2024](https://www.wearedevelopers.com/magazine/471-the-future-of-open-source-a-deep-dive-scott-chacon-at-wearedevelopers-world-congress-2024) ## Related Jobs - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Staff Engineer, Security Engineering Partners](https://www.wearedevelopers.com/jobs/ext/1187268-staff-engineer-security-engineering-partners) at **Twilio** - [Senior Software Engineer, Enterprise Products](https://www.wearedevelopers.com/jobs/ext/1841248-senior-software-engineer-enterprise-products) at **GitHub** - [Software Engineer II, Security](https://www.wearedevelopers.com/jobs/ext/131510-software-engineer-ii-security) at **GitHub**