You secured your code dependencies, is that enough?
Anant Shrivastava
Question : Have you heard about
Why?
Supply Chain issues are age old trust issues
…and it’s not going anywhere anytime soon…
Effect across the globe in Govt Japan US EU India UK
Why now?
Work done by Dependabot in last ~5 months
What is Software Bill of Material
SCA Source Composition Analysis Tools
Question : Raise your hands if
Software Supply Chains beyond Code chain
What other chains?
A set of chain that existed 5 months back
A Chain that exists now (besides previous)
Simplified Supply Chain view
Why do they matter
Developer Machine : Why lucrative
Show me data don’t just imagine
Case studies: WYS Is not WYG
Chrome Browser
What can a browser extension do
Cookie Monster
Visual Studio Code
Visual Studio Marketplaces
Homebrew
Unexpected places for code execution
Unexpected places or code execution
Notepad++
Notepad ++ Impersonation
Cursor oh Cursor
Rulefiles
C.I. / C.D. Systems
DEFENDING CI CD
Teamcity exploitation
Container Images
Dependency Caching Servers
Bait and Switch
Rogue Maintainers
So, what's the plan?
Next Steps
Chrome Extension Auditing
End Point Visibility
GitHub and Github Actions
GitHub and Github Actions
Consumer : Vetting Process needed (Vet)
Consumer : Vetting Process Needed (Overlay)
Cloud Auditing
Broad Visualization of Software Supply Chain
Supply-chain Levels for Software Artifacts
OWASP SCVS ~ SSDF
Open Software Supply Chain Attack Reference
Can of worms that I have not touched
Thanks for listening & open to Questions?