Software Supply Chain

Every dependency, GitHub Action, and container base image a pipeline pulls in is a trust decision. This covers dependency review practices, artifact pinning and signing, SBOM generation, and the MITRE ATT&CK supply-chain technique these controls actually defend against.

MITRE ATT&CKT1195.001Compromise Software Dependencies and Development Tools — the specific sub-technique dependency pinning and SBOM practices defend against