[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-supply-chain-security::en":3,"gloss-cluster-supply-chain-security::en":26,"gloss-next-supply-chain-security::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"supply-chain-security","dev-tools","Software Supply-Chain Security","Software supply-chain security is about protecting everything that goes into building and shipping your software — third-party dependencies, build tools, CI\u002FCD pipelines, container base images, and the developer accounts with access — not just the code you write yourself. The threat is that attackers increasingly target the weakest link upstream: a compromised npm package, a malicious dependency update, a poisoned build server, or stolen CI credentials that inject code everyone downstream trusts. Incidents like the SolarWinds breach and repeated malicious-package campaigns on npm and PyPI made this a board-level concern. Defenses include pinning dependency versions, verifying package integrity, generating an SBOM, scanning for known vulnerabilities, signing artifacts, and locking down CI permissions. For AI\u002FSaaS builders the uncomfortable truth is that most of your running code is code you didn't write, so trusting it blindly is the real risk. Practical note: pin and lock dependencies, review what you add before adding it, restrict what your CI can access, and automate vulnerability scanning so a bad dependency is caught before it ships.","Supply-chain security protects everything that ships your software — dependencies, build tools, CI\u002FCD, base images, developer accounts — not just your own code.",null,[11,14,17,20,23],{"slug":12,"name":13},"ci-cd","Continuous Integration \u002F Continuous Deployment (CI\u002FCD)",{"slug":15,"name":16},"package-manager","Package Manager",{"slug":18,"name":19},"sast","Static Application Security Testing (SAST)",{"slug":21,"name":22},"secrets-management","Secrets Management",{"slug":24,"name":25},"software-bill-of-materials","Software Bill of Materials (SBOM)",[27,31,34,38,41,44,47,50,53,54,57,60],{"slug":28,"category":5,"name":29,"updated_at":30},"agent","Agent","2026-08-24T02:46:36+00:00",{"slug":32,"category":5,"name":33,"updated_at":30},"ai-code-assistant","AI Coding Assistant",{"slug":35,"category":5,"name":36,"updated_at":37},"api-gateway","API Gateway","2026-08-24T02:46:37+00:00",{"slug":39,"category":5,"name":40,"updated_at":37},"api-versioning","API Versioning",{"slug":42,"category":5,"name":43,"updated_at":30},"autonomous-agent","Autonomous Agent",{"slug":45,"category":5,"name":46,"updated_at":37},"blue-green-deployment","Blue-Green Deployment",{"slug":48,"category":5,"name":49,"updated_at":37},"canary-deployment","Canary Deployment",{"slug":51,"category":5,"name":52,"updated_at":37},"chaos-engineering","Chaos Engineering",{"slug":12,"category":5,"name":13,"updated_at":30},{"slug":55,"category":5,"name":56,"updated_at":37},"circuit-breaker","Circuit Breaker",{"slug":58,"category":5,"name":59,"updated_at":37},"cli","Command-Line Interface (CLI)",{"slug":61,"category":5,"name":62,"updated_at":37},"cloud-development-environment","Cloud Development Environment (CDE)"]