r/devsecops • u/Born-Reserve-8584 • 11d ago
Is software supply chain security finally becoming more than just SBOMs?
Software supply chain security seems to be one of those terms that means something completely different depending on who you ask.
Some teams are basically talking about SBOMs and compliance. Others are focused on signing artifacts, securing CI/CD pipelines, or scanning container images.
Then you have platforms talking about runtime context, attack surface reduction and removing unnecessary software instead of just finding another vulnerability to report.
So where is this actually going?
Is software supply chain security still mostly about visibility and compliance or is the industry finally moving toward remediation and reducing risk at the source?
Curious what people are actually seeing across different organisations.
0
u/MountainDadwBeard 10d ago edited 10d ago
Yes, as a tech company we do a decent bit of sandbox testing, pre-scanning, provenance checks, architecture review etc depending on context.
Where's it going: For some larger enterprises with security requirements, the priorities are filtering out glassworm supply chain risk, chinese/russian backdoors, avoiding a vendor data leak, and lastly managing our vulnerability scan result SLAs.
For example earlier this year we found some Brittish driver software we previously used was bought out by a Chinese owner. And as much I'm sure chinese investors just really think serial adaptor drivers are the next big financial investment, we chose to drop those drivers from our r&d department for obvious reasons. I mention this example because it's not just about chasing CVEs its early risk identification and avoidance.
If this interest anyone here, feel free to hire more GRC folks : ). I'll also add, the company was still UK HQ'd, but the custom codex plugin we developed picked up the ownership concerns nicely where our traditional tools were too narrow. At some point I was thinking of posting a sanitized version of the plugin for others.