{"id":87591,"date":"2023-10-25T07:00:00","date_gmt":"2023-10-25T11:00:00","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=87591"},"modified":"2025-11-13T20:32:32","modified_gmt":"2025-11-13T18:32:32","slug":"our-vision-securing-the-entire-software-supply-chain","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/","title":{"rendered":"Our vision: Securing the entire software supply chain"},"content":{"rendered":"<p>The use of open source software has quickly exposed all parts of the software development process as part of the overall attack surface, and has even lead to the creation of&nbsp;&nbsp;new attack types.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Organizations must take steps at every stage of the software supply chain to ensure developers\u2019 environments. Enterprises must also make sure processes and secured, so you aren\u2019t leaving your business vulnerable to next-generation SCS attacks, like AI package hallucinations, dependency confusion, typosquatting, and repojacking.&nbsp;<\/p>\n\n\n\n<p>Let\u2019s dive into a brief history of how \u201csupply chain security\u201d has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how Checkmarx is proactively building new solutions to address this complex and ongoing issue.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\"><strong>Our mission to secure the entire software supply chain<\/strong><\/h2>\n\n\n\n<p>For the past 10 years, security professionals have been trained that before you release code, all high vulnerabilities need to be identified and fixed. But over the last few years especially, the world has changed. According to GitHub, open source is now the foundation of more than&nbsp;<a href=\"https:\/\/github.blog\/2022-11-17-octoverse-2022-10-years-of-tracking-open-source\/#:~:text=Today%2C%20more%20than%2094%20million,(and%20developers)%20build%20applications.\">90%<\/a>&nbsp;of the world\u2019s software.&nbsp;&nbsp;Organizations are now facing a shifting attack landscape, along with an overwhelming number of vulnerabilities. The attack landscape is moving from the application itself, to where there are new vulnerabilities and weaknesses \u2013 in the process surrounding your development, and the components you use to build your application.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\"><strong>What software supply chain security really means<\/strong><\/h2>\n\n\n\n<p>Traditionally, supply chain security was to a way to gain visibility and mitigate 3rd-party code vulnerabilities through SCA. But as time went on and as new attack types emerged. In a 2021 executive order,&nbsp;<a href=\"https:\/\/checkmarx.com\/blog\/sbom-what-it-is-and-why-you-should-care\/\">software bill of materials<\/a>, or SBOMs, are required for all software sold to the US federal government. The mandate underscores the importance of an accurate list of all open-source software ingredients found in a software-based product<em>.<\/em>&nbsp;The market quickly realized that the scope of software supply chain attacks, and how we prevent these attacks, go way beyond SBOMs and malicious packages.<em>&nbsp;&nbsp;<\/em><\/p>\n\n\n\n<p>Supply chain security is defined as a specific aspect of application security that focuses on protecting the software development&nbsp;process&nbsp;and the&nbsp;components&nbsp;used in that process.<em>&nbsp;<\/em>Software supply chain security is not a single solution; it is a discipline.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\"><strong>Supporting the SLSA Framework<\/strong><\/h2>\n\n\n\n<p>The&nbsp;<a href=\"https:\/\/slsa.dev\/\">Supply-chain Levels for Software Artifacts (SLSA) framework<\/a>, developed in collaboration with the OpenSSF and Google, addresses the growing concern of software supply chain security, offering a structured approach to assessing and improving the integrity of software components used in development.&nbsp;<\/p>\n\n\n\n<p class=\"has-text-align-center\"><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/SLSA-1.png\" alt=\"\" class=\"wp-image-95005\"><\/figure>\n<\/div>\n\n\n<p>SLSA introduces key concepts like artifacts, provenance, digests, immutable references, and build integrity, that provide a systematic way for the software industry to secure the development lifecycle and promote consistent security standards.<\/p>\n\n\n\n<p>Understanding that the full scope of SCS is beyond a single tool, Checkmarx has implemented a broader strategy to cover things outside of your typical application security posture management, in full alignment with the SLSA framework.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\"><strong>How Checkmarx is helping you secure your software supply chain<\/strong><\/h2>\n\n\n\n<p>Today, Checkmarx is providing expert guidance and proven solutions to manage open-source risk, along with new and exciting solutions to start protecting your entire supply chain today.&nbsp;<\/p>\n\n\n\n<p>In the last few years, one of the&nbsp;<a href=\"https:\/\/checkmarx.com\/press-releases\/as-malicious-open-source-packages-proliferate-checkmarx-announces-supply-chain-threat-intelligence-for-faster-easier-identification-of-potential-threats\/#:~:text=%E2%80%9COur%20Checkmarx%20Labs%20supply%20chain,after%20they've%20been%20reported.\">biggest emerging threats<\/a>&nbsp;have been malicious packages \u2013 notably different from vulnerable packages. In the SLSA framework, malicious packages are a form of dependency attack where attackers inject or contribute malicious code into open source projects that your developers download and build into your applications. Once downloaded, the attacker&#8217;s malicious code is running within your applications, with whatever unknown intent the package carries.&nbsp;<\/p>\n\n\n\n<p>Checkmarx SCA, introduced in 2021,&nbsp;&nbsp;was a major step in helping organizations identify and start reporting on their open-source vulnerabilities. We were the first vendor to include malicious package detection inside our SCA solution. Since then, our research team has inspected over 7.6 million open-source packages for all kinds of threats, finding 200,000+ malicious packages.<strong>&nbsp;<\/strong>We make that threat intelligence available to you, either in our SCA product, where findings are in the portal or directly in developers\u2019 IDE, or through an API-based threat intelligence feed.&nbsp;<\/p>\n\n\n\n<p>Checkmarx SCA enables automated SBOM generation, and Checkmarx Container Security, which works with Checkmarx SCA, identifies vulnerabilities in open-source packages included in container images. Together with our partners at Sysdig, we&nbsp;<a href=\"https:\/\/checkmarx.com\/press-releases\/checkmarx-integrates-sysdig-runtime-insights-for-faster-prioritization-of-cloud-native-application-vulnerabilities\/\">recently announced<\/a>&nbsp;runtime insights, so organizations can get the full picture of pre-production and deployment, gaining visibility into which container images are in-use and prioritize the ones that pose the most risk.<\/p>\n\n\n\n<p>We realized customers need support in prioritization, especially with all these newly discovered vulnerabilities, so we released&nbsp;<a href=\"https:\/\/checkmarx.com\/blog\/exploitable-path-how-to-solve-a-static-analysis-nightmare\/\">Exploitable Path<\/a>. It\u2019s a unique feature that allows our customers to prioritize vulnerabilities in open-source libraries.&nbsp;&nbsp;<\/p>\n\n\n\n<p>When you look at the SLSA framework, we also have always led the way in terms of identifying Infrastructure-as-Code (IaC) misconfigurations. We are the driving force behind the most downloaded open-source tool in this area \u2013&nbsp;<a href=\"https:\/\/github.com\/Checkmarx\/kics\">Keep Infrastructure as Code Secure<\/a>, or KICS for short.<\/p>\n\n\n\n<p>All of these are important tools in managing open-source risk, but we are not stopping there.&nbsp;<\/p>\n\n\n\n<p>Since GenAI&nbsp;&nbsp;is becoming a popular resource for developers to generate code, a&nbsp;variety of new SCS attacks have recently emerged, such as:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AI hallucinations: These are false data points or patterns that AI models might &#8220;perceive&#8221; due to adversarial inputs or misinterpretations, which can be exploited by malicious actors.<\/li>\n\n\n\n<li>Prompt injections: Threat actors can manipulate AI models by introducing or \u201cinjecting\u201d specially crafted prompts, tricking the system into undesired behaviors or outputs.<\/li>\n\n\n\n<li>AI secret leakage: There&#8217;s a potential risk of AI models inadvertently revealing confidential information they were trained on, offering a goldmine for cybercriminals.<\/li>\n<\/ul>\n\n\n\n<p class=\"has-text-align-center\"><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/CheckAI-2.jpg\" alt=\"\" class=\"wp-image-95006\"><\/figure>\n<\/div>\n\n\n<p>In August, Checkmarx introduced the&nbsp;<a href=\"https:\/\/checkmarx.com\/press-releases\/checkmarx-announces-checkai-with-groundbreaking-plugin-to-detect-and-prevent-attacks-against-chatgpt-generated-code\/\">industry\u2019s first plugin<\/a>&nbsp;to detect and prevent attacks against ChatGPT-generated code. The plugin enables developers to easily scan their ChatGPT-generated code for vulnerabilities within the ChatGPT interface, receive instant feedback on potential vulnerabilities or validation of open source packages, and employ protection against malicious open-source packages.&nbsp;<\/p>\n\n\n\n<p>Now, we\u2019re leading the way again, and broaden the definition of software supply chain security, beyond just malicious packages, to every component in, and every tool used to build your applications. As part of the Checkmarx One 3.0 launch, we\u2019re taking it&nbsp;&nbsp;one step further, introducing two new capabilities \u2013Secrets Detection and Project Scorecard.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\"><strong>Prevent secrets from leaking on external tools with Secrets Detection&nbsp;&nbsp;<\/strong><\/h2>\n\n\n\n<p>Secrets, such as passwords, API keys, cryptographic keys, and other confidential data, are a frequent target of a distributed supply-chain attack.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Secrets can easily be mistakenly shared on external tools like slack, confluence, twitch, and documentation pages.<\/p>\n\n\n\n<p>Secret detection isn\u2019t new \u2013 we have one of the most popular open-source tools for secret detection. 2MS from Checkmarx has over 2 million downloads, and anyone can&nbsp;<a href=\"https:\/\/github.com\/Checkmarx\/2ms\">get started today by detecting secrets<\/a>&nbsp;such as login credentials, API keys, SSH keys and more hidden in code, content systems, chat applications and more.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/image-19-2.png\" alt=\"\" class=\"wp-image-95007\"><\/figure>\n<\/div>\n\n\n<p>If you are a Checkmarx One user, Secret Detection is now available directly in the Checkmarx One platform.&nbsp;&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-6\"><strong>Tackle the most vulnerable projects first with Project Scorecard&nbsp;<\/strong><\/h2>\n\n\n\n<p>One of the latest additions to the Checkmarx Supply Chain Security portfolio is Project Scorecard, which enables organizations to check their own projects quickly and see the most vulnerable or at-risk projects, allowing enterprises to prioritize which to tackle first.<\/p>\n\n\n\n<p>Project Scorecard leverages the format from a popular tool, the&nbsp;<a href=\"https:\/\/securityscorecards.dev\/\">OSSF Scorecard<\/a>, which assesses open-source projects for security risks through a series of automated checks.&nbsp;<\/p>\n\n\n\n<p>These checks cover different parts of the software supply chain including source code, build, and dependencies, and assigns each check a score of 1-10. An auto-generated \u201csecurity score\u201d helps users as they decide the trust, risk, and security posture for their specific application.&nbsp;<\/p>\n\n\n\n<p>While an important tool in combating the uptick of open source software attacks, open-source projects are only a portion of the projects in your application. Checking the process and components of owned projects is an important element in securing the total software supply chain.&nbsp;&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/image-20-2.png\" alt=\"\" class=\"wp-image-95008\"><\/figure>\n<\/div>\n\n\n<p>With Project Scorecard, users can auto-generate a security score for their own projects based on a series of checks, including:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Binary Artifacts \u2013 Is the project free of checked-in binaries?&nbsp;<ul><li>Branch Protection \u2013 Does the project use branch protection?&nbsp;<\/li><\/ul>\n<ul><li>CI Tests \u2013 Does the project run tests in CI, e.g., GitHub Actions, Prow?&nbsp;<\/li><\/ul>\n<ul><li>Code review \u2013 Does the project practice code review before code is merged?&nbsp;<\/li><\/ul>\n<ul><li>Dangerous workflow \u2013 Does the project avoid dangerous coding patterns?&nbsp;<\/li><\/ul>\n<ul class=\"wp-block-list\">\n<li>Vulnerabilities \u2013 Does the project have unfixed vulnerabilities?&nbsp;<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n\n\n\n<p>By utilizing the Project Scorecard, as part of the Checkmarx Supply Chain module, we allow enterprises to quickly see the most vulnerable or at-risk projects, and ultimately help prioritize which to tackle first.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-7\"><strong>Taking the next step to secure your software supply chain&nbsp;&nbsp;<\/strong><\/h2>\n\n\n\n<p>It\u2019s important to take steps to secure your software supply chain today; detecting supply chain attacks in code packages, securing your developer\u2019s evolving workstations supports rapid development while reducing risk.&nbsp;<\/p>\n\n\n\n<p>Current Checkmarx One or Checkmarx SCA customers will have access to all these tools within the platform.&nbsp;<\/p>\n\n\n\n<p>If you\u2019re not already a Checkmarx One customer, you can start securing your software supply chain today with&nbsp;<a href=\"https:\/\/github.com\/Checkmarx\/2ms\">too many secrets (2MS)<\/a>, available as an open-source project on GitHub.<\/p>\n\n\n\n<p>We\u2019re incredibly excited to announce these new features to help you secure your software supply chain, but we\u2019re only getting started. The work of securing the software supply chain is never done, as bad actors identify innovative new ways to capitalize on gaps in process and components, so stay tuned for more exciting announcements.&nbsp;<\/p>\n\n\n\n<p>If you\u2019d like to learn more register now to join us for our technical deep dive webinar on Nov 6th,<a href=\"https:\/\/info.checkmarx.com\/checkmarx-one-3.0-lp\"> \u201cSecure your software supply chain\u201d.<\/a><\/p>","protected":false},"excerpt":{"rendered":"<p>The use of open source software has quickly exposed all parts of the software development process as part of the overall attack surface, and has even lead to the creation of&nbsp;&nbsp;new attack types.&nbsp;&nbsp; Organizations must take steps at every stage of the software supply chain to ensure developers\u2019 environments. Enterprises must also make sure processes [&hellip;]<\/p>\n","protected":false},"author":86,"featured_media":87690,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[85,84,844],"tags":[87,441,444,190,403,434,385],"class_list":["post-87591","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-application-security-trends","category-blog","category-supply-chain-security","tag-appsec","tag-checkmarx-one-3-0","tag-deep-dive-webinar","tag-english","tag-leadership","tag-scs","tag-supply-chain-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Our vision: Securing the entire software supply chain<\/title>\n<meta name=\"description\" content=\"Let\u0092s dive into a brief history of how \u0093supply chain security\u0094 has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how Checkmarx is proactively building new solutions to address this complex and ongoing issue.\u00a0\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Our vision: Securing the entire software supply chain\" \/>\n<meta property=\"og:description\" content=\"Let\u0092s dive into a brief history of how \u0093supply chain security\u0094 has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how Checkmarx is proactively building new solutions to address this complex and ongoing issue.\u00a0\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2023-10-25T11:00:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-13T18:32:32+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1336\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kaitlyn Huff\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kaitlyn Huff\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/\"},\"author\":{\"name\":\"Kaitlyn Huff\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/153f776e9fabc54c52b782ab0a45f473\"},\"headline\":\"Our vision: Securing the entire software supply chain\",\"datePublished\":\"2023-10-25T11:00:00+00:00\",\"dateModified\":\"2025-11-13T18:32:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/\"},\"wordCount\":1683,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg\",\"keywords\":[\"AppSec\",\"Checkmarx One 3.0\",\"Deep Dive Webinar\",\"English\",\"Leadership\",\"SCS\",\"SSCS\"],\"articleSection\":[\"Application Security Trends &amp; Insights\",\"Blog\",\"Supply Chain Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/\",\"name\":\"Our vision: Securing the entire software supply chain\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg\",\"datePublished\":\"2023-10-25T11:00:00+00:00\",\"dateModified\":\"2025-11-13T18:32:32+00:00\",\"description\":\"Let\u0092s dive into a brief history of how \u0093supply chain security\u0094 has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how Checkmarx is proactively building new solutions to address this complex and ongoing issue.\u00a0\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg\",\"width\":2560,\"height\":1336,\"caption\":\"Supply chain\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/153f776e9fabc54c52b782ab0a45f473\",\"name\":\"Kaitlyn Huff\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_86.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_86.jpg\",\"caption\":\"Kaitlyn Huff\"},\"url\":\"https:\/\/checkmarx.com\/author\/kaitlynhuff\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Our vision: Securing the entire software supply chain","description":"Let\u0092s dive into a brief history of how \u0093supply chain security\u0094 has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how Checkmarx is proactively building new solutions to address this complex and ongoing issue.\u00a0","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/","og_locale":"en_US","og_type":"article","og_title":"Our vision: Securing the entire software supply chain","og_description":"Let\u0092s dive into a brief history of how \u0093supply chain security\u0094 has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how Checkmarx is proactively building new solutions to address this complex and ongoing issue.\u00a0","og_url":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2023-10-25T11:00:00+00:00","article_modified_time":"2025-11-13T18:32:32+00:00","og_image":[{"width":2560,"height":1336,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg","type":"image\/jpeg"}],"author":"Kaitlyn Huff","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Kaitlyn Huff","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/"},"author":{"name":"Kaitlyn Huff","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/153f776e9fabc54c52b782ab0a45f473"},"headline":"Our vision: Securing the entire software supply chain","datePublished":"2023-10-25T11:00:00+00:00","dateModified":"2025-11-13T18:32:32+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/"},"wordCount":1683,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg","keywords":["AppSec","Checkmarx One 3.0","Deep Dive Webinar","English","Leadership","SCS","SSCS"],"articleSection":["Application Security Trends &amp; Insights","Blog","Supply Chain Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/","url":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/","name":"Our vision: Securing the entire software supply chain","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg","datePublished":"2023-10-25T11:00:00+00:00","dateModified":"2025-11-13T18:32:32+00:00","description":"Let\u0092s dive into a brief history of how \u0093supply chain security\u0094 has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how Checkmarx is proactively building new solutions to address this complex and ongoing issue.\u00a0","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/our-vision-securing-the-entire-software-supply-chain\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2023\/10\/Supply-chain-\u2013-Blog-300ppi-scaled-1.jpg","width":2560,"height":1336,"caption":"Supply chain"},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/153f776e9fabc54c52b782ab0a45f473","name":"Kaitlyn Huff","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_86.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/06\/avatar_86.jpg","caption":"Kaitlyn Huff"},"url":"https:\/\/checkmarx.com\/author\/kaitlynhuff\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/87591","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/86"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=87591"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/87591\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/87690"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=87591"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=87591"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=87591"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}