Tampered components or pipelines distribute compromised artifacts through the platform.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Theoretical construct: explains a term, principle, or mental model.
Concrete cog in the system that works inside larger relationships.
A software supply chain compromise occurs when attackers manipulate dependencies, build systems, or distribution paths to inject code into software.
The term combines supply-chain risk with software engineering and security incidents. A compromised supplier, package repository, or build pipeline can turn a trusted artefact into a distribution path.
Trace an artefact’s provenance and integrity from source to deployment. Reduce implicit trust through signed builds, reproducible processes, vetted dependencies, least privilege, and independent verification. A scan alone does not prove a secure supply chain.
Malicious code enters through a component, account, tool, or process.
Provenance records where an artefact came from and how it was produced.
Signatures and controls indicate whether an artefact changed after release.
Supply-chain compromise requires security controls beyond first-party code. It differs from general testing: tests assess behaviour, while provenance and integrity secure the trust basis of delivered components.
Where this building block is located in the topic model.
No structure path available.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.