{"id":98879,"date":"2024-11-19T18:05:25","date_gmt":"2024-11-19T16:05:25","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?p=98879"},"modified":"2025-12-16T23:42:42","modified_gmt":"2025-12-16T21:42:42","slug":"checkmarx-advances-software-supply-chain-security","status":"publish","type":"post","link":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/","title":{"rendered":"Checkmarx Advances Software Supply Chain Security"},"content":{"rendered":"<p>Software supply chain security (SSCS) attacks are on the rise.<\/p>\n\n\n\n<p>In fact, according to <a href=\"https:\/\/www.infoworld.com\/article\/3712543\/protecting-against-software-supply-chain-attacks.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Infoworld<\/a>, \u201cwe are in the midst of a rapid surge in software supply chain attacks,\u201d with a staggering 742% annual increase, resulting in costs exceeding $4 million. <a href=\"https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2022-03-07-gartner-identifies-top-security-and-risk-management-trends-for-2022\" target=\"_blank\" rel=\"noreferrer noopener\">Gartner<\/a> predicted that by 2025, 45% of organizations worldwide will have experienced attacks on their software supply chains, a three-fold increase from 2021.<\/p>\n\n\n\n<p>The growing number of high-profile SSCS attacks and data breaches (such as <a href=\"https:\/\/www.npr.org\/2021\/04\/16\/985439655\/a-worst-nightmare-cyberattack-the-untold-story-of-the-solarwinds-hack\">SolarWinds<\/a>, <a href=\"https:\/\/www.wired.com\/story\/notpetya-cyberattack-ukraine-russia-code-crashed-the-world\/\">NotPetya<\/a>, <a href=\"https:\/\/thehackernews.com\/2018\/04\/ccleaner-malware-attack.html\">CCleaner<\/a>, <a href=\"https:\/\/www.zdnet.com\/article\/anatomy-of-the-target-data-breach-missed-opportunities-and-lessons-learned\/\">Target<\/a>, <a href=\"https:\/\/www.wired.com\/story\/equifax-hack-china\/\">Equifax<\/a> and <a href=\"https:\/\/www.csoonline.com\/article\/571081\/the-kaseya-ransomware-attack-a-timeline.html\">Kaseya VSA<\/a>) have increased awareness of SSCS vulnerabilities. This alarming trend emphasizes the need for enterprises to allocate more resources into securing their software development and deployment processes, from code to cloud.<\/p>\n\n\n\n<p>But how did we get here? Fifteen years ago, most enterprises exclusively relied on internally developed code. Today, however, most modern code bases are largely built with open source packages and third-party code. While this shift accelerates development and fosters more innovative code, it also introduces more vulnerabilities \u2013 whether from human error, careless exposure of secret keys (passwords, encryption keys, and access tokens), or malicious third-party code. Additionally, the recent uptick in AI-generated code from digital assistants like ChatGPT, GitHub Copilot, and Codestral has further increased the risk of insecure code finding its way into enterprise applications.<\/p>\n\n\n\n<p>Like it or not, modern development requires the use of third-party codebases, despite the risks they may bring. That\u2019s why enterprises need a solution to effectively manage and mitigate the risks associated with these third-party libraries.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">AppSec Has Traditionally Focused on Internally Developed Code<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"434\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-1-1024x434.jpg\" alt=\"\" class=\"wp-image-99205\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-1-1024x434.jpg 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-1-300x127.jpg 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-1-768x326.jpg 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-1-1536x652.jpg 1536w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-1.jpg 1768w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><em> Figure 1 \u2013 Traditional application security focused only on finding vulnerabilities in proprietary code.<\/em><\/p>\n\n\n\n<p>Until recently, application security (AppSec) primarily focused on the code developed by the enterprise in-house. This made it easier to detect and remediate security vulnerabilities, because the code was exclusively written by their own developers. Vulnerability detection for these code bases generally relied on static application security testing (<a href=\"https:\/\/checkmarx.com\/cxsast-source-code-scanning\/\" target=\"_blank\" rel=\"noreferrer noopener\">SAST<\/a>) and dynamic application security testing (<a href=\"https:\/\/checkmarx.com\/checkmarx-dast\/\" target=\"_blank\" rel=\"noreferrer noopener\">DAST<\/a>).<\/p>\n\n\n\n<p>In fact, when Checkmarx was founded 18 years ago, we also focused on this traditional AppSec model, concentrating on securing the code developed internally by enterprises.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">Why Software Supply Chain Security Now?&nbsp;<\/h2>\n\n\n\n<p>What changed? In recent years, the importance of securing the software supply chain from code to cloud has grown steadily among enterprise CISOs, AppSec managers, DevOps teams, and developers.<\/p>\n\n\n\n<p>This shift is driven by four key factors:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Extensive use of open source packages and other third-party code<\/li>\n\n\n\n<li>Migration of applications to the cloud (cloud-native applications)<\/li>\n\n\n\n<li>Incorporation of automated compile\/deploy workflows (CI\/CD)<\/li>\n\n\n\n<li>Proliferation of attacks on the software supply chain<\/li>\n<\/ol>\n\n\n\n<p>These changes in modern development have introduced greater risks to software security than ever before. Securing applications now requires involvement from every stage of the software development lifecycle (SDLC), from code to cloud. To address these new threat vectors, Checkmarx developed a comprehensive, integrated solution that protects the entire software supply chain.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">SSCS Begins With SCA and Malicious Package Protection<\/h2>\n\n\n\n<p>Surveys indicate a dramatic increase in the use of open source libraries, with up to 97% of applications now incorporating open-source code. This statistic is not surprising, considering how open-source libraries significantly speed up development and reduce business costs.<\/p>\n\n\n\n<p>However, this new, increased use of open source code has also exposed enterprises to a massive new threat vector: both unintentional vulnerabilities and intentionally malicious code \u2013 both of which can be exploited.<\/p>\n\n\n\n<p>Checkmarx has adapted to the evolving risks in the software supply chain and has become a leader in addressing these open-source risks. How? Our Software Composition Analysis (SCA) solution provides enterprises with a strong protection against these types of malicious packages. Checkmarx\u2019 SCA solution:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Comprehensively discovers and itemizes all open-source packages used in applications (including transitive open-source dependencies)<\/li>\n\n\n\n<li>Identifies open-source packages containing vulnerable code, malicious code, or suspicious behavior (such as typosquatting, starjacking, and repojacking)<\/li>\n\n\n\n<li>Prioritizes remediation efforts using multiple analyses (e.g., reachability\/exploitable path analysis and SAST correlation)<\/li>\n\n\n\n<li>Provides AppSec teams and developers with specific and actionable remediation guidance<\/li>\n\n\n\n<li>Integrates with CI\/CD and IDE tools to smoothly integrate security testing and remediation workflows into existing deployment and development platforms<\/li>\n\n\n\n<li>Generates an industry-standard software bill of materials (SBOM)<\/li>\n\n\n\n<li>Detects legal and compliance risks associated with open source licensing issues<\/li>\n\n\n\n<li>Enforces policy rules to automatically send alerts and prevent builds based on a range of factors<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"329\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-2-1024x329.jpg\" alt=\"\" class=\"wp-image-99203\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-2-1024x329.jpg 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-2-300x96.jpg 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-2-768x247.jpg 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-2-1536x494.jpg 1536w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-2.jpg 1769w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><em> Figure 2 \u2013 The first step to expanding application security into software supply chain security is adding advanced SCA with malicious package protection.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-4\">Checkmarx One: Advanced AppSec Including SSCS<\/h2>\n\n\n\n<p>Unfortunately, even advanced SCA solutions are no longer enough to protect against SSCS attacks. To fully protect the software supply chain, Checkmarx now offers a complete suite of industry-leading solutions to secure both internally developed code and the software supply chain components that they consume.<\/p>\n\n\n\n<p>Checkmarx One is a code- to -cloud platform that provides an integrated SSCS solution that no enterprise can afford to be without. In addition to our SAST, DAST, SCA, and malicious package protection capabilities, Checkmarx One covers the entire software supply chain with the following capabilities:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>\n<a href=\"https:\/\/checkmarx.com\/product\/container-security\/\"><strong>Container Security<\/strong><\/a> \u2013 Identify and mitigate risks in container images, container infrastructure, and runtime code.<\/li>\n\n\n\n<li>\n<a href=\"https:\/\/checkmarx.com\/product\/checkmarx-one-assist\/\"><strong>AI Security<\/strong> <\/a>\u2013 Automatically scan AI-generated source code and referenced open-source libraries for vulnerable or malicious code.<\/li>\n\n\n\n<li>\n<strong><a href=\"https:\/\/checkmarx.com\/product\/iac-security\/\">IaC Security<\/a> <\/strong>\u2013 Secure cloud infrastructure with proactive vulnerability identification and misconfiguration detection.<\/li>\n\n\n\n<li>\n<a href=\"https:\/\/checkmarx.com\/product\/api-security\/\"><strong>API Security<\/strong><\/a> \u2013 Discover and remediate every API vulnerability.<\/li>\n\n\n\n<li>\n<strong><a href=\"https:\/\/checkmarx.com\/product\/secrets-detection\/\">Secrets Detection<\/a><\/strong> \u2013 Automatically discover the presence of sensitive credentials.<\/li>\n\n\n\n<li>\n<strong><a href=\"https:\/\/checkmarx.com\/product\/repository-health\/\">Repository Health<\/a><\/strong> \u2013 Get comprehensive health scorecards for software repositories.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"435\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-3-1-1024x435.jpg\" alt=\"\" class=\"wp-image-99204\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-3-1-1024x435.jpg 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-3-1-300x128.jpg 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-3-1-768x327.jpg 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-3-1-1536x653.jpg 1536w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/SSCS-blog-Figure-3-1.jpg 1766w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-center\"><em>Figure 3 \u2013 Checkmarx One delivers comprehensive code-to-cloud application security, including coverage for critical software supply chain dangers.<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\"> More About Our Newest Capabilities<\/h2>\n\n\n\n<p>Secrets Detection and Repository Health are the newest additions to the Checkmarx One suite aimed at protecting against software supply chain risks. Let\u2019s take a closer look at these new offerings:<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-6\">Secrets Detection<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" width=\"1258\" height=\"792\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/Secrets-Detection_nobg.webp\" alt=\"\" class=\"wp-image-99561\" style=\"width:551px;height:auto\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/Secrets-Detection_nobg.webp 1258w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/Secrets-Detection_nobg-300x189.webp 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/Secrets-Detection_nobg-1024x645.webp 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/Secrets-Detection_nobg-768x484.webp 768w\" sizes=\"(max-width: 1258px) 100vw, 1258px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"has-text-align-center\"><em>Figure 4 &#8211; Secrets Detection minimizes risk by identifying sensitive credentials that are at risk of being unintentionally exposed.<\/em><\/p>\n\n\n\n<p>Enterprises unintentionally expose <a href=\"https:\/\/www.wired.com\/story\/secret-hunting-bill-demirkapi\/\" target=\"_blank\" rel=\"noreferrer noopener\">thousands of secret credentials<\/a> in GitHub and other publicly accessible or insecure locations every day. This exposure can enable unauthorized access to your systems, potentially resulting in cyber-attacks, financial loss, and reputational damage. Once credentials are compromised, attackers can move laterally within systems to extract data, deploy malware, or launch further attacks on infrastructure, customers, and partners.<\/p>\n\n\n\n<p>Checkmarx\u2019 Secrets Detection minimizes risk by quickly identifying sensitive credentials that may be unintentionally exposed \u2013 and pinpoints which ones are still valid. With this insight, your development and security teams can quickly remediate issues by removing exposed secrets and updating them to prevent any unauthorized usage.<\/p>\n\n\n\n<p>Scanning for exposed secrets can be initiated on demand or manually with automatic triggers via SCM integration (e.g., pull request, build). Discovered secrets are automatically validated to determine if they are still in effect and thus potentially exploitable.<\/p>\n\n\n\n<p>This provides three key benefits:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Minimize supply chain risk by preventing the exposure of secret credentials, reducing the chance of attackers accessing your systems or stealing data.<\/li>\n\n\n\n<li>Improve regulatory compliance by meeting data protection requirements (e.g., GDPR, HIPAA, PCI DSS, SOX, FISMA, CCPA) and avoiding fines and reputational damage.<\/li>\n\n\n\n<li>Increase developer efficiency by allowing developers to initiate scans, review discovered secrets, and receive remediation guidance directly within their IDE.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-7\">Repository Health<\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" width=\"549\" height=\"386\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/Repository-Health-Small.png\" alt=\"\" class=\"wp-image-99291\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/Repository-Health-Small.png 549w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/Repository-Health-Small-300x211.png 300w\" sizes=\"(max-width: 549px) 100vw, 549px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"has-text-align-center\"><em>Figure 5 &#8211; Repository Health provides ongoing visibility into the security and maintenance health of the code repositories used in enterprise applications.<\/em><\/p>\n\n\n\n<p>Enterprises also need a reliable way to continuously evaluate the riskiness of the open-source code used in their applications, as well as a method to monitor the quality and security of the repositories containing their internally written code. <\/p>\n\n\n\n<p>Checkmarx\u2019 Repository Health maximizes the security posture of your software supply chain by continuously tracking health scores for all repositories in your applications. Scoring is based on more than a dozen key factors in areas, such as code quality, dependency management, CI\/CD best practices, and project maintenance.<\/p>\n\n\n\n<p>Repository Health can automatically scan repositories upon repository updates, ensuring up-to-date repo health metrics with no manual effort. Developers and security teams can also run on-demand repo health scans at any time via API, CLI, or the Checkmarx One UI.<\/p>\n\n\n\n<p>Additionally, repository health scores are included in Checkmarx One reports, providing visibility into \u2013 and efficient prioritization of \u2013 security vulnerabilities, code quality issues, and repository health risks, all in one place.<\/p>\n\n\n\n<p>The three key benefits this provides include: <\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Minimize supply chain risk \u2013 Visibility into the security health of open source components and your own code repositories that closes an important gap in software supply chain security.<\/li>\n\n\n\n<li>Efficient holistic risk prioritization \u2013 Identifying and prioritizing high-risk areas across the software supply chain that allows developers and security teams to focus their efforts on the most critical security issues.<\/li>\n\n\n\n<li>Enhanced transparency and communication \u2013 Clear, quantifiable metrics on the security posture of open source dependencies and first-party repositories that improve transparency and communication among stakeholders.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-8\">Learn More<\/h2>\n\n\n\n<p>Given the wide range of threat vectors facing enterprise applications and the software supply chain, deploying the most comprehensive and effective security solutions is essential. And these solutions must also cultivate an excellent developer experience to encourage adoption and support seamless, efficient workflows.<\/p>\n\n\n\n<p>Relying on a hodge-podge of different tools to protect your supply chain is no longer viable \u2013 it is expensive, inefficient, and difficult to maintain. To protect your enterprise from data breaches or other system infiltrations unified platform that covers all your bases. And that\u2019s where Checkmarx comes in.<\/p>\n\n\n\n<p><a href=\"https:\/\/checkmarx-my.sharepoint.com\/personal\/joel_rosenstein_checkmarx_com\/Documents\/Documents\/Articles%20&amp;%20Blog%20Posts\/contactus\">Contact us<\/a> for a <a href=\"https:\/\/checkmarx-my.sharepoint.com\/personal\/joel_rosenstein_checkmarx_com\/Documents\/Documents\/Articles%20&amp;%20Blog%20Posts\/demorequest\">free demo<\/a> of Checkmarx One and discover the industry\u2019s best solution for securing your enterprise\u2019s applications and the software supply chain.<\/p>","protected":false},"excerpt":{"rendered":"<p>Software supply chain security (SSCS) attacks are on the rise. In fact, according to Infoworld, \u201cwe are in the midst of a rapid surge in software supply chain attacks,\u201d with a staggering 742% annual increase, resulting in costs exceeding $4 million. Gartner predicted that by 2025, 45% of organizations worldwide will have experienced attacks on [&hellip;]<\/p>\n","protected":false},"author":118,"featured_media":98913,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[84,1283,844],"tags":[],"class_list":["post-98879","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-checkmarx-product-use-cases-guides","category-supply-chain-security"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Checkmarx Advances Software Supply Chain Security<\/title>\n<meta name=\"description\" content=\"Checkmarx enhances software supply chain security SSCS with advanced secrets detection and repository health solutions. Strengthen your defense against evolving threats. Explore our advancements in securing your software supply chain.\u200b\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Checkmarx Advances Software Supply Chain Security\" \/>\n<meta property=\"og:description\" content=\"Checkmarx enhances software supply chain security SSCS with advanced secrets detection and repository health solutions. Strengthen your defense against evolving threats. Explore our advancements in securing your software supply chain.\u200b\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:published_time\" content=\"2024-11-19T16:05:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-16T21:42:42+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Joel Rose\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joel Rose\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/\"},\"author\":{\"name\":\"Joel Rose\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/8cc863d656a4de523dab9b35c0756078\"},\"headline\":\"Checkmarx Advances Software Supply Chain Security\",\"datePublished\":\"2024-11-19T16:05:25+00:00\",\"dateModified\":\"2025-12-16T21:42:42+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/\"},\"wordCount\":1578,\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp\",\"articleSection\":[\"Blog\",\"Checkmarx Product News, Use Cases &amp; Guides\",\"Supply Chain Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/\",\"url\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/\",\"name\":\"Checkmarx Advances Software Supply Chain Security\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp\",\"datePublished\":\"2024-11-19T16:05:25+00:00\",\"dateModified\":\"2025-12-16T21:42:42+00:00\",\"description\":\"Checkmarx enhances software supply chain security SSCS with advanced secrets detection and repository health solutions. Strengthen your defense against evolving threats. Explore our advancements in securing your software supply chain.\u200b\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp\",\"width\":1200,\"height\":600,\"caption\":\"Guide to Open-Source Software Supply Chain Security\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/8cc863d656a4de523dab9b35c0756078\",\"name\":\"Joel Rose\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/03\/MicrosoftTeams-image-13-150x150.jpg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/03\/MicrosoftTeams-image-13-150x150.jpg\",\"caption\":\"Joel Rose\"},\"url\":\"https:\/\/checkmarx.com\/author\/joelr\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Checkmarx Advances Software Supply Chain Security","description":"Checkmarx enhances software supply chain security SSCS with advanced secrets detection and repository health solutions. Strengthen your defense against evolving threats. Explore our advancements in securing your software supply chain.\u200b","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/","og_locale":"en_US","og_type":"article","og_title":"Checkmarx Advances Software Supply Chain Security","og_description":"Checkmarx enhances software supply chain security SSCS with advanced secrets detection and repository health solutions. Strengthen your defense against evolving threats. Explore our advancements in securing your software supply chain.\u200b","og_url":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_published_time":"2024-11-19T16:05:25+00:00","article_modified_time":"2025-12-16T21:42:42+00:00","og_image":[{"width":1200,"height":600,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp","type":"image\/webp"}],"author":"Joel Rose","twitter_card":"summary_large_image","twitter_creator":"@checkmarx","twitter_site":"@checkmarx","twitter_misc":{"Written by":"Joel Rose","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#article","isPartOf":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/"},"author":{"name":"Joel Rose","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/8cc863d656a4de523dab9b35c0756078"},"headline":"Checkmarx Advances Software Supply Chain Security","datePublished":"2024-11-19T16:05:25+00:00","dateModified":"2025-12-16T21:42:42+00:00","mainEntityOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/"},"wordCount":1578,"publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp","articleSection":["Blog","Checkmarx Product News, Use Cases &amp; Guides","Supply Chain Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/","url":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/","name":"Checkmarx Advances Software Supply Chain Security","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp","datePublished":"2024-11-19T16:05:25+00:00","dateModified":"2025-12-16T21:42:42+00:00","description":"Checkmarx enhances software supply chain security SSCS with advanced secrets detection and repository health solutions. Strengthen your defense against evolving threats. Explore our advancements in securing your software supply chain.\u200b","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/blog\/checkmarx-advances-software-supply-chain-security\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/11\/blog_sscs_launch_2x-scaled-e1745548480622.webp","width":1200,"height":600,"caption":"Guide to Open-Source Software Supply Chain Security"},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]},{"@type":"Person","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/8cc863d656a4de523dab9b35c0756078","name":"Joel Rose","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/person\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/03\/MicrosoftTeams-image-13-150x150.jpg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/03\/MicrosoftTeams-image-13-150x150.jpg","caption":"Joel Rose"},"url":"https:\/\/checkmarx.com\/author\/joelr\/"}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/98879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/118"}],"replies":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/comments?post=98879"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/posts\/98879\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/98913"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=98879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/categories?post=98879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/tags?post=98879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}