We can all agree today that we really need to know what’s what with your software supply chain. The cloud native security company https://www.aquasec.com/ joined forces with the https://www.cisecurity.org/ to create the first formal software supply chain security guidelines: The https://workbench.cisecurity.org/communities/142. The guidelines cover the security basics for five software supply chain categories.

This is an open source tool for auditing your software supply chain to ensure guideline compliance.

With help from others who take securing software supply chains seriously, this could eventually set real standards for open source development security.

Related Articles