Software supply chain security protects the path from source to production: the open-source components you consume, the build systems that assemble them, the pipelines that run the builds, and the credentials those pipelines hold. Landmark incidents — compromised build servers, poisoned packages, leaked pipeline tokens — made the pipeline itself a first-class attack surface.
The attack surface, concretely
- Dependencies: malicious or vulnerable packages entering through manifests.
- Build systems: pipeline definitions and agents executing attacker-influenced code.
- Credentials: service connections and tokens a compromised build can exercise.
- Configuration: the security steps themselves, silently removed or never applied.
Defenses that compound
SCA and secrets scanning cover the component and credential layers. But the pipeline layer needs operational controls: knowing every pipeline, governing what runs in each, scoping the credentials each can use, and keeping an audit record of changes to any of it. A hardened pipeline nobody monitors is one refactor away from unhardened.

