Skip to main content
📬 Get weekly Production AI insights Practical notes on Kubernetes, AI infrastructure and platform engineering. No spam. Subscribe free
Open Source Trust and Supply Chain Security
Open Source

Trust in Open Source: Securing the Software Supply Chain for

Sovereign infrastructure demands verified software. Build trust with SBOMs, SLSA attestations, reproducible builds, and curated open source registries.

LB
Luca Berton
· 1 min read

Every modern application is built on open-source dependencies. The average project has hundreds of transitive dependencies, each one a potential attack vector. Software supply chain security is not about trusting open source less — it is about verifying more.

The Supply Chain Attack Surface

Recent high-profile attacks:

  • SolarWinds (2020): Build system compromised, malicious code injected into updates
  • Codecov (2021): CI/CD tool compromised, credentials harvested
  • Log4Shell (2021): Critical vulnerability in ubiquitous logging library
  • xz Utils (2024): Maintainer social engineering — malicious code inserted over 2 years
  • PyPI/npm malware: Thousands of typosquatting packages published monthly

The SLSA Framework

Supply chain Levels for Software Artifacts (SLSA, pronounced “salsa”) provides a maturity model:

LevelRequirementsProtection
SLSA 1Build process documentedKnow how artifacts were built
SLSA 2Hosted build service, signed provenancePrevent tampering after build
SLSA 3Hardened build platform, non-falsifiable provenancePrevent tampering during build
SLSA 4Two-party review, hermetic buildsPrevent insider threats

Implementing Supply Chain Security

Step 1: Software Bill of Materials (SBOM)

Generate an SBOM for every build:

# Generate SBOM with Syft
syft dir:. -o spdx-json > sbom.spdx.json

# Or with Trivy
trivy fs . --format spdx-json --output sbom.spdx.json

# For container images
syft myapp:latest -o cyclonedx-json > sbom.cdx.json

Step 2: Vulnerability Scanning

Scan dependencies continuously:

# GitHub Actions: scan on every PR
- name: Trivy vulnerability scan
  uses: aquasecurity/trivy-action@master
  with:
    scan-type: 'fs'
    scan-ref: '.'
    format: 'sarif'
    output: 'trivy-results.sarif'
    severity: 'CRITICAL,HIGH'

Step 3: Artifact Signing

Sign all build artifacts with Sigstore:

# Sign a container image
cosign sign --key cosign.key ghcr.io/my-org/myapp:v1.0.0

# Verify a signed image
cosign verify --key cosign.pub ghcr.io/my-org/myapp:v1.0.0

Step 4: Admission Control

Only allow signed, scanned images in your cluster:

apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: verify-image-signatures
spec:
  validationFailureAction: Enforce
  rules:
    - name: check-signature
      match:
        resources:
          kinds: [Pod]
      verifyImages:
        - imageReferences: ["ghcr.io/my-org/*"]
          attestors:
            - entries:
                - keys:
                    publicKeys: |-
                      -----BEGIN PUBLIC KEY-----
                      ...
                      -----END PUBLIC KEY-----

Step 5: Dependency Review

Before merging dependency updates:

# GitHub Actions: dependency review
- name: Dependency Review
  uses: actions/dependency-review-action@v4
  with:
    fail-on-severity: high
    deny-licenses: AGPL-3.0, GPL-3.0
    allow-dependencies-licenses: MIT, Apache-2.0, BSD-2-Clause, BSD-3-Clause

Kubernetes-Specific Supply Chain

  • Image provenance: Require SLSA provenance attestations for all images
  • Base image management: Maintain curated, scanned base images
  • Helm chart verification: Sign and verify Helm charts
  • Operator trust: Verify operator images from OperatorHub
#supply-chain #sbom #slsa #trust #open-source
Share:
Luca Berton — The Production AI Expert, Docker Captain

Luca Berton

The Production AI Expert · Docker Captain · KubeCon Speaker

15+ years in enterprise infrastructure. Author of 8 technical books, creator of Ansible Pilot (1M+ YouTube views, 648K site users). Former Red Hat engineer. Speaker at KubeCon EU 2026 and Red Hat Summit 2026.

Free 30-min Production AI consultation

Book Now