Software supply chain attacks increased 742% between 2019 and 2025. From SolarWinds to xz-utils, attackers increasingly target the build and distribution pipeline rather than the application itself.
The Attack Surface
Source Code → Build System → Artifacts → Registry → Deployment
↑ ↑ ↑ ↑ ↑
Compromised Poisoned Tampered Hijacked Malicious
dependency build env binary package configEvery stage is a potential attack vector.
SLSA Framework
Supply-chain Levels for Software Artifacts (SLSA) defines four maturity levels:
| Level | Requirements | Protection |
|---|---|---|
| SLSA 1 | Build process documented | Basic provenance |
| SLSA 2 | Hosted build service, signed provenance | Tamper resistance |
| SLSA 3 | Hardened build platform, verified source | Compromise resistance |
| SLSA 4 | Hermetic, reproducible builds | Maximum assurance |
Implementing SLSA in CI/CD
# GitHub Actions with SLSA provenance
name: Build and Sign
on: push
jobs:
build:
runs-on: ubuntu-latest
permissions:
id-token: write
contents: read
attestations: write
steps:
- uses: actions/checkout@v4
- name: Build container image
run: docker build -t myapp:${{ github.sha }} .
- name: Generate SBOM
uses: anchore/sbom-action@v0
with:
image: myapp:${{ github.sha }}
format: spdx-json
output-file: sbom.spdx.json
- name: Sign with Sigstore
run: |
cosign sign --yes \
ghcr.io/org/myapp:${{ github.sha }}
- name: Attest SBOM
run: |
cosign attest --yes \
--predicate sbom.spdx.json \
--type spdxjson \
ghcr.io/org/myapp:${{ github.sha }}
- name: Generate SLSA provenance
uses: slsa-framework/slsa-github-generator/.github/workflows/generator_container_slsa3.yml@v2.0.0Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →SBOM Generation
Software Bill of Materials lists every component:
# Generate SBOM for container image
syft myapp:latest -o spdx-json > sbom.json
# Generate SBOM for source code
cdxgen -o bom.json -t nodejs .
# Scan SBOM for vulnerabilities
grype sbom:sbom.json --fail-on criticalDependency Verification
Don't trust, verify:
# Kubernetes admission policy: require signed images
apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
name: verify-image-signatures
spec:
validationFailureAction: Enforce
rules:
- name: verify-cosign-signature
match:
any:
- resources:
kinds: [Pod]
verifyImages:
- imageReferences:
- "ghcr.io/org/*"
attestors:
- entries:
- keyless:
subject: "https://github.com/org/*"
issuer: "https://token.actions.githubusercontent.com"Dependency Management Best Practices
- Pin dependencies — Use exact versions, not ranges
- Lock files — Commit lock files (
package-lock.json,pnpm-lock.yaml,Cargo.lock) - Private registry mirror — Cache and scan packages before use
- Automated updates — Dependabot/Renovate with automated testing
- Scorecard checks — OpenSSF Scorecard for dependency health
- License compliance — Automated license scanning (FOSSA, Snyk)
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Runtime Verification
Trust doesn't end at deploy:
- Image allowlisting — Only approved images run in production
- Runtime integrity — Detect modifications to running containers
- Network policies — Restrict unexpected outbound connections
- Behavioral monitoring — Flag processes that deviate from baselined behavior
The Regulatory Push
- US Executive Order 14028 — Requires SBOM for government software
- EU Cyber Resilience Act — SBOM mandatory for products sold in EU (2027)
- PCI DSS 4.0 — Software inventory requirements for payment processing
- DORA — Supply chain risk management for EU financial sector
FAQ
Do I really need SBOMs? Yes. Regulatory requirements are expanding, and SBOMs are your first line of defense when the next Log4Shell hits.
How do I handle transitive dependencies? SBOM tools (Syft, cdxgen) automatically discover transitive dependencies. Vulnerability scanners (Grype, Trivy) check the full tree.
What's the overhead of signing and attestation? Minimal. Sigstore keyless signing adds < 10 seconds to CI/CD. The security benefit far outweighs the cost.
---
Ready to go deeper?
This article is part of a hands-on learning path. Continue building your skills with our course catalog on CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Chainguard Enforce Supply Chain
Chainguard Enforce validates container supply chain integrity in Kubernetes using SLSA provenance, SBOMs, and image signatures. Learn how to enforce supply.
Sigstore Container Image Signing
Sigstore provides keyless signing for container images and software artifacts. Learn how to sign images with Cosign, verify signatures in Kubernetes.
Cosign Container Image Signing
Cosign signs and verifies container images using keyless signing with Sigstore. Learn how to sign images in CI/CD, verify signatures before deployment.
Sops Encrypted Secrets in Git
SOPS encrypts secret values in YAML, JSON, and dotenv files while keeping keys readable. Learn how to use SOPS with age, AWS KMS, or GCP KMS.
Spacelift Terraform Orchestration
Spacelift orchestrates Terraform, OpenTofu, and Pulumi with policies, drift detection, and approval workflows. Learn how Spacelift compares to Terraform Cloud.
Spatial Computing for Enterprise
Deploy spatial computing applications with AR/VR infrastructure, 3D content pipelines, and edge computing for enterprise digital twin visualizations.
Explore topics
Browse more articles on the topics covered here.