DevSec Station

← DevSec Station4 Jun · 7 min

Supply Chain Is More Than Just Dependencies

Supply Chain Is More Than Just Dependencies4 Jun7 min

Most developers think software supply chain security starts and ends with dependencies. But modern supply chain attacks don't stop there. Attackers look for paths into your software, and those paths often run through developers, CI/CD systems, build tools, deployment pipelines, and other trusted parts of the software delivery process. This episode is sponsored by Maze. In this episode of DevSec Station, Tanya Janca explains why the software supply chain is much bigger than libraries and pac...