Software Supply Chain Attribute Integrity (SCAI)

10/11/2022
by   Marcela S. Melara, et al.
0

The Software Supply Chain Attribute Integrity, or SCAI (pronounced "sky"), specification proposes a data format for capturing functional attribute and integrity information about software artifacts and their supply chain. SCAI data can be associated with executable binaries, statically- or dynamically-linked libraries, software packages, container images, software toolchains, and compute environments. As such, SCAI is intended to be implemented as part of an existing software supply chain attestation framework by software development tools or services (e.g., builders, CI/CD pipelines, software analysis tools) seeking to capture more granular information about the attributes and behavior of the software artifacts they produce. That is, SCAI assumes that implementers will have appropriate processes and tooling in place for capturing other types of software supply chain metadata, which can be extended to add support for SCAI.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/11/2021

Integrating On-chain and Off-chain Governance for Supply Chain Transparency and Integrity

Integrating on-chain and off-chain data storage for decentralised and di...
research
12/19/2021

What are Weak Links in the npm Supply Chain?

Modern software development frequently uses third-party packages, raisin...
research
02/17/2023

A Review of Attacks Against Language-Based Package Managers

The liberalization of software licensing has led to unprecedented re-use...
research
04/26/2023

On the Way to SBOMs: Investigating Design Issues and Solutions in Practice

Software Bill of Materials (SBOM), offers improved transparency and supp...
research
07/11/2019

Supply chain malware targets SGX: Take care of what you sign

Malware attacks represent a significant part of today's security threats...
research
08/30/2023

Quantitative Toolchain Assurance

The software bill of materials (SBOM) concept aims to include more infor...
research
11/04/2022

Tutorial and Practice in Linear Programming: Optimization Problems in Supply Chain and Transport Logistics

This tutorial is an andragogical guide for students and practitioners se...

Please sign up or login with your details

Forgot password? Click here to reset