Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2
This is my final deep dive into the software supply chain ecosystem. Across 3-reports, I’ve provided a full breakdown of this ecosystem, covering, and analyzing over 20+ companies. I have spoken to many founders and security leaders on this topic. I have some exciting topics that will be published over the upcoming weeks exploring newer categories, like Next-Gen SIEMs / Security Analytics, Identity and SOC automation platforms in cybersecurity. Today’s piece provides a discussion on software supply chain security platform vendors and provides a core spotlight on several solutions being adopted within the industry. On Thursday, I will be a guest at this event titled ASPM—Deep Dive with Chris Hughes, where we will discuss some of these software supply chain topics and what defines a full ASPM vendor. After 8 months of research into many vendors across the software supply chain security ecosystem, I’ve observed that to become a full and successful software supply chain vendor - you need t
Defining A Software Supply Chain Security Platform & Exploring New Techniques, Part 2 What defines a successful software supply chain platform? Exploring new techniques like reachability analysis, secrets, and open-source communities. SACR and Nipun Gupta Apr 22, 2024 16 1 Share This is my final deep dive into the software supply chain ecosystem. Across 3 reports, I’ve provided a full breakdown of this ecosystem and analyzed over 20+ companies. I have spoken to many founders and security leaders on this topic. I have some exciting topics that will be published over the upcoming weeks exploring
saved by
related reading
- Software Supply Chain Security (Part 1)softwareanalyst.substack.com
- A Deep Dive Into The Cloud & Application Security Ecosystemsoftwareanalyst.substack.com
- OpenSSF Scorecardsecurityscorecards.dev
- Project Glasswing: Securing critical software for the AI era \ Anthropicanthropic.com
- Getting Secure Beyond CVE Scanningpulse.latio.tech
- The ultimate guide to SBOMsabout.gitlab.com
- OWASP Foundation - The Open Source Foundation for Application Securityowasp.org
- State of DevSecOps | Datadogdatadoghq.com
- The Rise Of Application Security Posture Management (ASPM) Platformssoftwareanalyst.substack.com
- Fixing Rust's supply chain security: The good, the bad and the uglykerkour.com
- The Operating System for Modern Securitydepthfirst.com
- Security incident disclosure — July 2026huggingface.co