Leanpub Header

Skip to main content

The Software Trust Chain

Securing Code, Dependencies, Builds, and Deployments in the AI Era

The Software Trust Chain
This book is 100% completeLast updated on 2026-09-20

Software supply chains are now a critical attack surface. The Software Trust Chain explores how to secure code, dependencies, builds, CI/CD, containers and deployments in the age of generative AI and autonomous coding agents, focusing on practical engineering principles that remain useful as tools and platforms change.

Minimum price

$19.00

$29.00

You pay

Author earns

$

Also available for 1 book credit with a Reader Membership

PDF
EPUB
WEB
APP
206
Pages
About

About

About the Book

This book provides a comprehensive technical reference on securing the modern software supply chain, from source code through dependencies, build systems, CI/CD pipelines, containers, infrastructure as code, and production deployment, with particular attention to how generative AI and autonomous coding agents transform the threat landscape. It is written for experienced software engineers, DevOps and platform engineers, security engineers, architects, and engineering managers who need deep understanding of mechanisms, trade-offs, and implementation strategies rather than high-level summaries or tool surveys. The goal is to make the material durable: by focusing on principles, architectures, and engineering practices, this book will remain useful even as individual tools and platforms evolve.

Author

About the Author

Steve Publications

Steve is a technology professional with more than 20 years of experience in software development, server infrastructure, cybersecurity, vulnerability research and reverse engineering. Throughout his career, he has designed, secured, analyzed and tested complex software and infrastructure, with a particular focus on understanding how systems fail and how they can be made more secure.

Outside of work, Steve enjoys sharing knowledge with the technology community. He collaborates with researchers, industry experts and technology professionals to write practical books covering software development, cybersecurity, cloud computing, networking, DevOps, artificial intelligence and enterprise technologies. His books focus on practical learning through clear explanations, real-world examples and hands-on exercises. With more than two decades of industry experience, his goal is to help IT professionals, students and technology enthusiasts build useful skills and stay current in a rapidly changing industry.

We believe readers deserve to know how our books are created. Most of our authors are not native English speakers, so we use AI to help translate, proofread manuscripts, fix grammar, improve sentence structure and make technical explanations easier to read. AI is used as an editing tool only. It does not replace the research, technical knowledge or hands-on experience behind our books. Some of our authors also prefer to remain anonymous for privacy or professional reasons. In those cases, we publish their work under a different name. The author's name may be different, but the quality of the content and our review process remain the same.

Every book is written, reviewed and maintained by experienced technology professionals, with contributions from our private technical community of more than 420 engineers and researchers. We spend far more time validating technical accuracy and keeping our content up to date than generating text. We are always interested in working with experienced professionals who have deep expertise in a particular technology or domain. If you would like to publish a book with us or help review an existing manuscript, we'd love to hear from you. Send us a message describing your area of expertise. We are especially interested in niche technologies, specialized skills and emerging topics that are underrepresented in existing technical literature.

If you look through the contents of our books, you'll see practical examples, detailed explanations and material that is regularly updated. Our goal is to publish books that professionals can actually rely on, not low-effort AI-generated content. If you ever feel that one of our books does not meet that standard, Leanpub offers a 60-day money-back guarantee. Feel free to request a refund if you are not satisfied with your purchase.

Contents

Table of Contents

Securing Code, Dependencies, Builds, and Deployments in the AI Era

Introduction

Chapter 1: What Is a Software Supply Chain

  1. The Invisible Infrastructure Behind Every Release
  2. From Source to Runtime: A Complete Journey
  3. Why Application Security Is Not Enough
  4. Trust in a Distributed World
  5. The Cost of Getting It Wrong
  6. How This Book Is Organized

Chapter 2: How We Got Here

  1. The Monolith Era and Its Security Assumptions
  2. Open Source as an Engine of Growth
  3. The CI/CD Revolution
  4. Containers, Cloud, and Infrastructure Abstraction
  5. The Explosion of Package Ecosystems
  6. When Software Began Generating Software
  7. The Structural Factors

Chapter 3: Foundational Security Principles

  1. Zero Trust and Its Real Meaning
  2. Least Privilege at Every Boundary
  3. Defense in Depth Without Illusion
  4. Assume Breach, Verify Everything
  5. Separation of Duties in Automated Systems
  6. Security as Engineering, Not Policy

Chapter 4: Source Control and Code Ownership

  1. Git and the Trust Model of Version Control
  2. Repository Access and Identity
  3. Code Review as a Security Control
  4. Branch Protection and Release Controls
  5. Fork-Based Development and External Contributors
  6. Secrets in Source and Accidental Exposure

Chapter 5: Dependency Ecosystems

  1. How Package Managers Actually Work
  2. The Growth of Transitive Dependencies
  3. Trust Models for Package Publishers
  4. Version Resolution and Its Security Implications
  5. Lockfiles, Pinning, and Reproducibility
  6. Private vs. Public Registries and Proxy Caching

Chapter 6: Build Systems and Artifacts

  1. The Build as a Transformation Pipeline
  2. Build Dependencies and Their Risks
  3. Reproducible and Deterministic Builds
  4. Build Environment Isolation
  5. Caching and Its Attack Surfaces
  6. Artifact Integrity from Source to Output

Chapter 7: CI/CD Pipelines

  1. What CI/CD Automates and What It Trusts
  2. Pipeline Definitions as Code and as Targets
  3. Runner Security and Shared Infrastructure
  4. Secrets in Pipelines
  5. Cross-Repository and Trigger Attacks
  6. Designing for Integrity and Observability

Chapter 8: Containers and Image Supply Chains

  1. The Container Image as a Supply Chain Artifact
  2. Base Image Trust and Inherited Vulnerabilities
  3. Image Building and Multi-Stage Security
  4. Registry Security and Access Control
  5. Scanning Images and Knowing What to Do With Results
  6. Signing Images and Enforcing Admission Policies

Chapter 9: Infrastructure as Code

  1. IaC as Code and as Configuration
  2. Module and Provider Dependencies
  3. State Management and Security
  4. Drift Detection and Unauthorized Changes
  5. Policy as Code and Guardrails
  6. The Supply Chain of Platform Definitions

Chapter 10: Deployment and Runtime Environments

  1. The Trust Chain Into Production
  2. Environment Isolation and Segmentation
  3. Deployment Strategies and Rollback Security
  4. Runtime Protection and Attack Surface Reduction
  5. Service Meshes and Zero Trust Networking
  6. Observability as a Security Signal

Chapter 11: Package Attacks

  1. Typosquatting and Lookalike Packages
  2. Dependency Confusion and Internal Name Shadowing
  3. Malicious Packages and Dropper Patterns
  4. Compromised Maintainers and Account Takeover
  5. Dependency Substitution and Version Manipulation

Chapter 12: Repository and Code Attacks

  1. Poisoned Commits in Third-Party Dependencies
  2. Malicious Pull Requests
  3. Repository Compromise and Key Signing Key Theft
  4. Maintainer and Organization Takeover
  5. Social Engineering Against Open Source
  6. Case Study: XZ Utils and the Anatomy of a Near Miss

Chapter 13: Build and Pipeline Attacks

  1. Build Tool and Plugin Compromise
  2. CI/CD Configuration Attacks
  3. Runner Exploitation and Shared Infrastructure Abuse
  4. Artifact Tampering Between Build and Deploy
  5. Supply-Chain Injection via Environment Variables
  6. Case Study: SolarWinds and the Build-Environment Attack
  7. Case Study: Codecov and the CI Script Compromise

Chapter 14: Container and Infrastructure Attacks

  1. Poisoned Container Images
  2. Registry Compromise and Access Escalation
  3. Malicious IaC Modules and Providers
  4. Infrastructure Hijacking via Supply Chain
  5. Kubernetes Supply Chain Attacks

Chapter 15: Secrets, Keys, and Identity

  1. Where Secrets Live and How They Leak
  2. Hard-Coded and Accidental Secrets
  3. Key Management for Signing and Encryption
  4. Identity in Automated Systems
  5. Rotating Credentials and Revoking Access

Chapter 16: Provenance and Attestation

  1. What Provenance Means and Why It Matters
  2. Provenance Formats and Specifications
  3. Generating Attestations in Pipelines
  4. Verifying Attestations Downstream
  5. Limits of Provenance and Trust on First Use

Chapter 17: SBOMs and Visibility

  1. What an SBOM Is and What It Is Not
  2. SPDX, CycloneDX, and Other Formats
  3. Generating SBOMs Across Build Stages
  4. Using SBOMs for Vulnerability Assessment
  5. SBOM Accuracy and False Positives
  6. SBOMs in Regulation and Compliance

Chapter 18: Digital Signatures and Trust Infrastructures

  1. What Signatures Protect and What They Do Not
  2. Key Management and Signing Operations
  3. Sigstore, Fulcio, and Rekor
  4. Package Signing and Trusted Publishing
  5. Signing Keys as High-Value Targets
  6. Building a Signing Strategy

Chapter 19: SLSA and Security Frameworks

  1. What SLSA Specifies and Why It Exists
  2. The Levels and What They Require
  3. Achieving SLSA Compliance Incrementally
  4. SLSA and Other Standards: NIST, CISA, OpenSSF
  5. When Frameworks Help and When They Hinder
  6. Measuring Security Posture Without Theater

Chapter 20: Securing AI-Assisted Development

  1. How AI Coding Assistants Actually Work
  2. Hallucinated Dependencies and Nonexistent Packages
  3. Vulnerability Patterns in AI-Generated Code
  4. Prompt Injection in Development Workflows
  5. AI Tools as Supply-Chain Dependencies
  6. Securing the AI Development Pipeline

Chapter 21: Autonomous Agents and the Next Frontier

  1. What Autonomous Agents Can Do Today
  2. Agent Identity and Authorization
  3. Terminal and Environment Access
  4. Repository Interaction and Merge Authority
  5. Production Deployment by Agents
  6. Designing Safe Agent Environments

Chapter 22: AI Models, Plugins, and Datasets as Dependencies

  1. Models as Software Artifacts
  2. Dataset Provenance and Poisoning
  3. Plugin and Extension Trust
  4. Fine-Tuning and Custom Model Supply Chains
  5. Registry Security for AI Artifacts

Chapter 23: Reference Architectures

  1. The Small Team: Maximum Security with Minimum Overhead
  2. The Growing SaaS Company: Scaling Controls with Velocity
  3. The Large Enterprise: Governance at Scale
  4. The Regulated Organization: Compliance Without Paralysis
  5. The Open Source Project: Security Without Central Control
  6. The Cloud-Native Platform: Supply Chain as a Service

Chapter 24: Assessing and Hardening Your Supply Chain

  1. Creating an Inventory of Your Supply Chain
  2. Mapping Trust Boundaries
  3. Threat Modeling for Supply Chains
  4. Prioritizing Risks and Quick Wins
  5. Establishing Security Policies
  6. Rolling Out Controls Incrementally

Chapter 25: Operations, Monitoring, and Response

  1. What to Monitor in the Supply Chain
  2. Detection Patterns and Alerting
  3. Incident Response for Supply-Chain Compromise
  4. Recovery, Reroll, and Remediation
  5. Post-Incident Learning
  6. Metrics That Matter

Chapter 26: Governance and Organization

  1. Who Owns the Supply Chain
  2. Responsibilities Across Teams
  3. Vulnerability Disclosure and Coordination
  4. Patching, Exceptions, and Risk Acceptance
  5. Third-Party and Vendor Risk
  6. Reporting Up and Measuring Progress

Chapter 27: Tradeoffs and Engineering Decisions

  1. Security vs. Velocity: Beyond the False Dichotomy
  2. Automation vs. Human Judgment
  3. Centralized vs. Distributed Control
  4. Open Source Contributions and Security Friction
  5. When Controls Create False Confidence
  6. Making Tradeoffs Explicit and Sustainable

Chapter 28: The Future of Software Supply-Chain Security

  1. Increasingly Autonomous Development
  2. Code Review in the Age of AI
  3. New Models of Trust and Verification
  4. Continuous Generation and Continuous Validation
  5. Regulatory Trajectories
  6. What Will Last and What Will Change

Conclusion

References

Get the free sample chapters

Click the buttons to get the free sample in PDF or EPUB, or read the sample online here

The Leanpub 60 Day 100% Happiness Guarantee

Within 60 days of purchase you can get a 100% refund on any Leanpub purchase, in two clicks.

See full terms...

Earn $8 on a $10 Purchase, and $16 on a $20 Purchase

We pay 80% royalties on purchases of $7.99 or more, and 80% royalties minus a 50 cent flat fee on purchases between $0.99 and $7.98. You earn $8 on a $10 sale, and $16 on a $20 sale. So, if we sell 5000 non-refunded copies of your book for $20, you'll earn $80,000.

(Yes, some authors have already earned much more than that on Leanpub.)

In fact, authors have earned over $15 million writing, publishing and selling on Leanpub.

Learn more about writing on Leanpub

Free Updates. DRM Free.

If you buy a Leanpub book, you get free updates for as long as the author updates the book! Many authors use Leanpub to publish their books in-progress, while they are writing them. All readers get free updates, regardless of when they bought the book or how much they paid (including free).

Most Leanpub books are available in PDF (for computers) and EPUB (for phones, tablets and Kindle). The formats that a book includes are shown at the top right corner of this page.

Finally, Leanpub books don't have any DRM copy-protection nonsense, so you can easily read them on any supported device.

Learn more about Leanpub's ebook formats and where to read them

Write and Publish on Leanpub

You can use Leanpub to easily write, publish and sell in-progress and completed ebooks and online courses!

Leanpub is a powerful platform for serious authors, combining a simple, elegant writing and publishing workflow with a store focused on selling in-progress ebooks.

Leanpub is a magical typewriter for authors: just write in plain text, and to publish your ebook, just click a button. (Or, if you are producing your ebook your own way, you can even upload your own PDF and/or EPUB files and then publish with one click!) It really is that easy.

Learn more about writing on Leanpub