2000 character limit reached
Journey to the Center of Software Supply Chain Attacks (2304.05200v1)
Published 11 Apr 2023 in cs.CR and cs.SE
Abstract: This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool "Risk Explorer for Software Supply Chains" to explore such information and we discuss its industrial use-cases.