Tag: Supply Chain Security
All the articles with the tag "Supply Chain Security".
Selecting more than one tag in the sidebar shows only posts that have every selected tag.
- #Private Repository#DevSecOps#Supply Chain Security
Private Repositories Security Review Process
A practical process for reviewing, approving, and continuously reassessing third-party artifacts before internal use.
4 min read - #AWS#ECR#EKS
Private ECR Delivery Architecture for Private EKS
A defense-in-depth design for delivering approved private ECR artifacts to private EKS workloads.
Updated:15 min read - #Contribution#Supply Chain Security#NIST SP 800-204
Private Registries and Package Mirrors: What I Contributed to the SEAL Security Frameworks
A new SEAL Security Frameworks page on internal package registries - what mirroring defends against, how routing blocks dependency confusion, and why the registry becomes a trust component in its own right.
11 min read - #Contribution#CI/CD Security#Supply Chain Security
Policy as Code Through the CI/CD Pipeline: What I Contributed to the SEAL Security Frameworks
A four-page section on policy as code across the CI/CD pipeline, mapped to NIST SP 800-204D, merged into the SEAL Security Frameworks.
11 min read - #AI#AI Supply Chain#Supply Chain Security
The AI Software Supply Chain Is Under Attack
A field guide to AI-era supply chain attacks - the objects at risk, how to screen them, and why AI coding raises the stakes.
11 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CD Pipelines
Supply chain security measures also apply to controls during the CD process.
4 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Code Commits
Appropriate forms of testing should be performed before code commits
2 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Integrity of Evidence Generation During Software Updates
How to ensure the integrity of evidence generation during software updates
6 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Pull-Push Operations on Repositories
Deep dive into secure Pull-Push Operations on Repositories referring to NIST SP 800-204D
6 min read - #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Build
Introduce the requirements for secure build and associated tools to secure your build stage in CI/CD pipeline.
19 min read