skip to content

Software Supply Chain Security

You will learn to secure what you ship, not just what you wrote: proving where an artifact came from, what is inside it, and that nobody tampered with the pipeline that built it. After SolarWinds and xz-utils this is the area senior DevSecOps interview loops probe hardest.

on this pageshow

explore

questions

328 · 9 sections

How can a build produce a backdoored artifact when every source file is clean?

level: juniorimportance: must knowfreq 64%
basics
~20 s

Because the artifact is made by the build, not by the repository. Anything that runs during the build - a build script, a plugin, a build-time dependency, the compiler image, a packaging step - can add code that appears in no source file.

open as a page

A team installs its internal CLI by piping a hosted install script into a shell - what supply chain risk does that create?

level: juniorimportance: must knowfreq 66%
basics
~20 s

It runs whatever that URL returns at that moment, with the caller's full privileges and no version, review or integrity check. Anyone who can write to the hosting location therefore runs code on every laptop and every CI job.

open as a page

In SUNBURST, xz-utils, event-stream, Codecov and ua-parser-js, what was each entry point?

level: juniorimportance: must knowfreq 70%
basics
~20 s

Five different doors. SUNBURST came through a compromised build system, xz-utils through a contributor who earned maintainer trust, event-stream through inherited maintainership, Codecov through a tampered delivery script, and ua-parser-js through a stolen publisher account.

open as a page

Why does installing an npm dependency execute that package's code before your build starts?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Many package managers let a package declare install hooks, scripts the manager runs automatically as part of installing it. Installing is therefore code execution, not a file copy, and it happens before your tests or scanners ever run.

open as a page

Why is installing a PyPI package your AI assistant suggested but nobody recognises risky?

level: juniorimportance: must knowfreq 62%
basics
~20 s

AI assistants invent plausible package names that were never published. Attackers collect those hallucinated names, register them on the public index, and wait for someone to install one. The name looks right precisely because a model generated it.

open as a page

What do the OSV, NVD and GHSA advisory databases each assert about a vulnerable package?

level: juniorimportance: must knowfreq 62%
basics
~20 s

NVD enriches a CVE record with a severity score and product applicability. GHSA describes the flaw per package ecosystem with a package name and affected version range. OSV is a schema and aggregator normalising many feeds into ecosystem-native ranges.

open as a page

Why does changing one line inside a committed lockfile count as a code change?

level: juniorimportance: must knowfreq 60%
basics
~20 s

A lockfile line names the exact package version, the source it is fetched from and the bytes accepted as that release. Editing it swaps different executable code into the build, with no source-file diff to review.

open as a page

What does a dependency's scope (test, build, runtime) change about whether a vulnerability finding is exploitable?

level: juniorimportance: must knowfreq 74%
basics
~10 s

Scope says where a package is needed, so it decides whether the package is in the artifact you deploy. A test-only library is absent from production and a production attacker cannot reach it.

open as a page

What do you check about an open-source library before adopting it in a production service?

level: juniorimportance: must knowfreq 72%
basics
~20 s

Check how many people really maintain it, whether releases and patch fixes still ship, whether it publishes a way to report a flaw privately, what the license is, how large the transitive tree is, and how much of it you actually need.

open as a page

What does an EPSS score of 0.08 on a CVE actually tell you about that vulnerability?

level: juniorimportance: must knowfreq 62%
basics
~10 s

EPSS estimates the probability a vulnerability will be exploited in the wild within 30 days. A score of 0.08 means roughly an 8 percent chance. It forecasts likelihood, not how damaging the flaw is.

open as a page

Why keep a queryable SBOM estate instead of regenerating SBOMs when an advisory lands?

level: juniorimportance: must knowfreq 58%
basics
~20 s

A stored, queryable estate answers 'where do we run this component, and at what version' in seconds. Regenerating means rebuilding every service at its deployed commit, which is slow and describes today's source rather than what is actually running.

open as a page

A vendor gave you an SBOM once at contract signature — what is it still worth a year on?

level: juniorimportance: must knowfreq 55%
basics
~20 s

Little, as a live inventory. An SBOM describes one build at one moment, so after a year of vendor releases it need not match the version you run. It survives as a baseline and as proof the vendor can produce one.

open as a page

In VEX, what are the four product statuses a statement can assign, and what does each claim?

level: juniorimportance: must knowfreq 58%
basics
~10 s

VEX defines four statuses for a product-and-vulnerability pair: not_affected, affected, fixed, and under_investigation. They state whether a known vulnerability is actually exploitable in that product, not whether the flawed component is present.

open as a page

In an SBOM, how does a purl differ from a CPE as a component identifier?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A purl is a coordinate computed from where a package actually came from: ecosystem, namespace, name, version. A CPE is a string from a curated dictionary that a human assigns, so it is often missing, duplicated or ambiguous.

open as a page

What does Syft do when you point it at a container image, and what does it not report?

level: juniorimportance: must knowfreq 68%
basics
~10 s

Syft unpacks the image's layers, runs per-ecosystem catalogers over the resulting filesystem to list installed packages, then serialises that list as SPDX or CycloneDX. It reports what is present, not whether anything is vulnerable.

open as a page

What does an npm provenance attestation assert about a package, and what does it not?

level: juniorimportance: must knowfreq 55%
basics
~20 s

It binds a published tarball's digest to the source repository, commit and CI workflow that built it, signed by that build's identity. It says nothing about whether the code is reviewed, safe, or free of vulnerabilities.

open as a page

In Sigstore's keyless flow, what does a Fulcio certificate bind, and how long is it valid?

level: juniorimportance: must knowfreq 55%
basics
~20 s

A Fulcio certificate binds a one-time public key, generated locally at signing time, to the OIDC identity and issuer in the token you presented. It stays valid for roughly ten minutes, so no signing key is ever stored.

open as a page

What does verifying a detached GPG .asc signature on a release tarball actually prove?

level: juniorimportance: must knowfreq 62%
basics
~20 s

It proves the file is byte-for-byte what the holder of that private key signed. It does not prove the key belongs to the project, that the build was clean, or that the code is safe.

open as a page

In keyless artifact signing, what happens to the private key that produced the signature?

level: juniorimportance: must knowfreq 62%
basics
~10 s

Keyless signing still uses a private key, but it is generated for that one signing operation and destroyed immediately afterwards. Nothing long-lived is left behind to store, guard, rotate, or lose.

open as a page

A vendor's Helm chart carries a valid signature from the vendor's release identity. What does that prove about the chart's behaviour?

level: juniorimportance: must knowfreq 80%
basics
~10 s

Nothing about behaviour. A signature binds a signer identity to one exact set of bytes: it says who vouched for them, not that the chart's contents, defaults or dependencies are safe to install.

open as a page

A firmware binary carries a valid vendor signature: what does that prove, and what can it not tell you?

level: juniorimportance: must knowfreq 66%
basics
~20 s

A valid signature proves only that the bytes are unchanged since signing and that a named identity vouched for them. It says nothing about which components are inside the binary or which source revision and build produced it.

open as a page

Why is build provenance from a long-lived, reused build machine worth less than from a single-use builder?

level: juniorimportance: must knowfreq 62%
basics
~20 s

A reused machine keeps state from earlier builds - caches, installed tools, leftover credentials, running processes - so an earlier job could have altered this build or what was recorded about it. A single-use environment removes that whole class of doubt.

open as a page

Does SLSA Build L3 provenance mean an artifact has no known vulnerable dependencies?

level: juniorimportance: must knowfreq 62%
basics
~10 s

No. The SLSA build track attests to how an artifact was produced and by which builder, not to what is inside it or whether those components are flawed. Vulnerable dependencies are a separate question.

open as a page

Your pipeline generates a provenance attestation for every build — what still has to happen for that to protect anything?

level: juniorimportance: must knowfreq 74%
basics
~20 s

A provenance statement proves nothing until something checks it. The control is a consumer verifying the statement against expectations fixed in advance and refusing the artifact when the check fails. Unverified attestations are metadata, not protection.

open as a page

When verifying build provenance, what does a consumer compare it against?

level: juniorimportance: must knowfreq 74%
basics
~20 s

Verification compares the statement against expectations written down in advance: the builder identity that produced the artifact, the source repository and revision it was built from, the build entry point, and the subject digest matching the artifact you actually hold.

open as a page

What does a default-deny outbound network policy on a build job actually prevent?

level: juniorimportance: must knowfreq 60%
basics
~20 s

Default-deny outbound stops build-time code reaching unapproved hosts: no exfiltrating secrets or source, no pulling a second-stage payload. It does not make a malicious dependency safe - the code still runs and can still corrupt the artifact.

open as a page

In a CI pipeline, which parts of the triggering event are attacker-controlled, and which are not?

level: juniorimportance: must knowfreq 68%
basics
~20 s

Anything a person typed is attacker-controlled: branch and tag names, commit messages, git author names, issue and comment bodies, pull request descriptions. Commit hashes, the repository name and the event type are produced by the platform, not by the submitter.

open as a page

When a fork's pull request triggers CI, what decides whether that run can read the base repository's secrets?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The trigger event, and whose context it runs in. Runs in the fork's context get no repository secrets and a read-only token; a second family of events runs in the base repository's context with full secrets and a write token.

open as a page

What makes a build hermetic, and why is a hermetic build not automatically deterministic?

level: juniorimportance: must knowfreq 68%
basics
~20 s

A hermetic build declares and pins every input before it starts and fetches nothing while it runs. It can still emit different bytes on each run, because embedded timestamps, absolute paths and file ordering vary independently of the inputs.

open as a page

Why should a CI build's automatic job token be scoped per job rather than per repository?

level: juniorimportance: must knowfreq 63%
basics
~20 s

A repository-wide grant is the ceiling for every job in it, so a docs-preview job inherits whatever the deploy job needs. Per-job scoping means code running in a low-value job cannot touch the release path.

open as a page

What does a shell and a package manager inside a container image give an attacker after a code-execution bug?

level: juniorimportance: must knowfreq 70%
basics
~20 s

They turn one code-execution bug into a working foothold: the attacker can explore the filesystem, read mounted credentials, fetch more tooling and pivot. An image holding only a static binary forces them to bring everything themselves.

open as a page

A change board approved an image by sha256 digest but the deployment names a mutable tag - what is the risk?

level: juniorimportance: must knowfreq 70%
basics
~20 s

The approval is not attached to what runs. Anyone able to push to that repository can re-aim the tag at different bytes, so the next pull fetches an image nobody reviewed, with no change to the deployment.

open as a page

Your pipeline signs every container image but nothing verifies the signature — what does that buy you?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Almost nothing on its own. A signature is only a claim until something refuses an artifact whose signature is missing or wrong. The value appears at the enforcement point: a pipeline gate, admission, or pull-time policy.

open as a page

Why does loading a model checkpoint saved as a Python pickle execute code, while safetensors does not?

level: juniorimportance: must knowfreq 58%
basics
~20 s

Pickle files carry executable instructions: unpickling can call arbitrary Python code while it rebuilds objects. A safetensors file holds only raw tensor bytes plus a JSON header, so loading it parses data and never runs code from the file.

open as a page

Why turn on image signature enforcement in audit mode before it starts blocking deploys?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Audit mode records which images would have been rejected without rejecting anything. That record is the blast radius: it exposes unsigned images, registries nobody documented and workloads with no owner, before a blocking rule takes production down.

open as a page

What does US Executive Order 14028 require from a company selling software to a federal agency?

level: juniorimportance: must knowfreq 65%
basics
~20 s

EO 14028 binds federal agencies, not vendors directly. It reaches sellers as a procurement condition: an agency may buy software only from a producer who attests to following NIST secure-development practices, and the agency may also require an SBOM.

open as a page

Under the EU Cyber Resilience Act, which products and companies are in scope?

level: juniorimportance: must knowfreq 68%
basics
~20 s

The CRA covers products with digital elements: hardware or software placed on the EU market, including firmware and components. The manufacturer, whoever sells it under their own name, carries the duties; importers and distributors carry lighter ones.

open as a page

What are the four practice groups in the NIST SSDF (SP 800-218), and what does each cover?

level: juniorimportance: must knowfreq 62%
basics
~20 s

SSDF has four groups: Prepare the Organization (PO), Protect the Software (PS), Produce Well-Secured Software (PW), and Respond to Vulnerabilities (RV). They cover org readiness, protecting code and releases, building software securely, and handling flaws found after release.

open as a page

How do you turn a customer's 200-line security schedule into a clause-by-clause answer?

level: middleimportance: must knowfreq 60%
basics
~20 s

Sort every clause into four buckets: already satisfied, partly satisfied, a real gap, or refused. For each satisfied clause name the evidence artifact, cost each gap in engineer-months, and get vague scope agreed in writing before signature.

open as a page

What triggers the EU Cyber Resilience Act's 24-hour early-warning report?

level: middleimportance: must knowfreq 62%
basics
~20 s

Becoming aware that a vulnerability in your product is being actively exploited, or that a severe incident affects its security. Within 24 hours you send an early warning to the coordinating national CSIRT and ENISA - not a public advisory.

open as a page

For a package registry account, why is a passkey phishing-resistant but a TOTP code not?

level: juniorimportance: must knowfreq 70%
basics
~20 s

A passkey signs a challenge bound to the registry's real domain, so a lookalike login page cannot relay it. A TOTP code is just six digits, which an attacker proxying your login replays within seconds.

open as a page

What is trusted publishing on a package registry, and how does it differ from a long-lived API token?

level: juniorimportance: must knowfreq 63%
basics
~20 s

Trusted publishing lets a registry accept a release from one specific CI workflow by verifying a short-lived OIDC identity token, instead of a long-lived API token stored as a CI secret. No reusable credential exists to steal.

open as a page

What does deprecating a published npm version do, and how does that differ from unpublishing it?

level: juniorimportance: must knowfreq 62%
basics
~20 s

Deprecating leaves the version fully installable and only attaches a message the registry shows at install time. Unpublishing removes the version so it can no longer be downloaded. One is a signal, the other is a withdrawal.

open as a page

When you publish a security advisory for your own library, what must it state about affected and fixed versions?

level: juniorimportance: must knowfreq 40%
basics
~20 s

Name the package identity in its ecosystem, the version where the vulnerable code was introduced, and the first fixed version on every release line you maintain. Ranges must be structured data, not prose like 'all earlier versions'.

open as a page

What is coordinated vulnerability disclosure, and how does it differ from full disclosure?

level: juniorimportance: must knowfreq 66%
basics
~20 s

Coordinated disclosure means the finder reports privately and gives the maintainer an agreed window to ship a fix before details go public. That window is the embargo. Full disclosure publishes the details straight away, with no window.

open as a page