Securing Code, Dependencies, Builds, and Deployments in the AI Era
Introduction
Chapter 1: What Is a Software Supply Chain
- The Invisible Infrastructure Behind Every Release
- From Source to Runtime: A Complete Journey
- Why Application Security Is Not Enough
- Trust in a Distributed World
- The Cost of Getting It Wrong
- How This Book Is Organized
Chapter 2: How We Got Here
- The Monolith Era and Its Security Assumptions
- Open Source as an Engine of Growth
- The CI/CD Revolution
- Containers, Cloud, and Infrastructure Abstraction
- The Explosion of Package Ecosystems
- When Software Began Generating Software
- The Structural Factors
Chapter 3: Foundational Security Principles
- Zero Trust and Its Real Meaning
- Least Privilege at Every Boundary
- Defense in Depth Without Illusion
- Assume Breach, Verify Everything
- Separation of Duties in Automated Systems
- Security as Engineering, Not Policy
Chapter 4: Source Control and Code Ownership
- Git and the Trust Model of Version Control
- Repository Access and Identity
- Code Review as a Security Control
- Branch Protection and Release Controls
- Fork-Based Development and External Contributors
- Secrets in Source and Accidental Exposure
Chapter 5: Dependency Ecosystems
- How Package Managers Actually Work
- The Growth of Transitive Dependencies
- Trust Models for Package Publishers
- Version Resolution and Its Security Implications
- Lockfiles, Pinning, and Reproducibility
- Private vs. Public Registries and Proxy Caching
Chapter 6: Build Systems and Artifacts
- The Build as a Transformation Pipeline
- Build Dependencies and Their Risks
- Reproducible and Deterministic Builds
- Build Environment Isolation
- Caching and Its Attack Surfaces
- Artifact Integrity from Source to Output
Chapter 7: CI/CD Pipelines
- What CI/CD Automates and What It Trusts
- Pipeline Definitions as Code and as Targets
- Runner Security and Shared Infrastructure
- Secrets in Pipelines
- Cross-Repository and Trigger Attacks
- Designing for Integrity and Observability
Chapter 8: Containers and Image Supply Chains
- The Container Image as a Supply Chain Artifact
- Base Image Trust and Inherited Vulnerabilities
- Image Building and Multi-Stage Security
- Registry Security and Access Control
- Scanning Images and Knowing What to Do With Results
- Signing Images and Enforcing Admission Policies
Chapter 9: Infrastructure as Code
- IaC as Code and as Configuration
- Module and Provider Dependencies
- State Management and Security
- Drift Detection and Unauthorized Changes
- Policy as Code and Guardrails
- The Supply Chain of Platform Definitions
Chapter 10: Deployment and Runtime Environments
- The Trust Chain Into Production
- Environment Isolation and Segmentation
- Deployment Strategies and Rollback Security
- Runtime Protection and Attack Surface Reduction
- Service Meshes and Zero Trust Networking
- Observability as a Security Signal
Chapter 11: Package Attacks
- Typosquatting and Lookalike Packages
- Dependency Confusion and Internal Name Shadowing
- Malicious Packages and Dropper Patterns
- Compromised Maintainers and Account Takeover
- Dependency Substitution and Version Manipulation
Chapter 12: Repository and Code Attacks
- Poisoned Commits in Third-Party Dependencies
- Malicious Pull Requests
- Repository Compromise and Key Signing Key Theft
- Maintainer and Organization Takeover
- Social Engineering Against Open Source
- Case Study: XZ Utils and the Anatomy of a Near Miss
Chapter 13: Build and Pipeline Attacks
- Build Tool and Plugin Compromise
- CI/CD Configuration Attacks
- Runner Exploitation and Shared Infrastructure Abuse
- Artifact Tampering Between Build and Deploy
- Supply-Chain Injection via Environment Variables
- Case Study: SolarWinds and the Build-Environment Attack
- Case Study: Codecov and the CI Script Compromise
Chapter 14: Container and Infrastructure Attacks
- Poisoned Container Images
- Registry Compromise and Access Escalation
- Malicious IaC Modules and Providers
- Infrastructure Hijacking via Supply Chain
- Kubernetes Supply Chain Attacks
Chapter 15: Secrets, Keys, and Identity
- Where Secrets Live and How They Leak
- Hard-Coded and Accidental Secrets
- Key Management for Signing and Encryption
- Identity in Automated Systems
- Rotating Credentials and Revoking Access
Chapter 16: Provenance and Attestation
- What Provenance Means and Why It Matters
- Provenance Formats and Specifications
- Generating Attestations in Pipelines
- Verifying Attestations Downstream
- Limits of Provenance and Trust on First Use
Chapter 17: SBOMs and Visibility
- What an SBOM Is and What It Is Not
- SPDX, CycloneDX, and Other Formats
- Generating SBOMs Across Build Stages
- Using SBOMs for Vulnerability Assessment
- SBOM Accuracy and False Positives
- SBOMs in Regulation and Compliance
Chapter 18: Digital Signatures and Trust Infrastructures
- What Signatures Protect and What They Do Not
- Key Management and Signing Operations
- Sigstore, Fulcio, and Rekor
- Package Signing and Trusted Publishing
- Signing Keys as High-Value Targets
- Building a Signing Strategy
Chapter 19: SLSA and Security Frameworks
- What SLSA Specifies and Why It Exists
- The Levels and What They Require
- Achieving SLSA Compliance Incrementally
- SLSA and Other Standards: NIST, CISA, OpenSSF
- When Frameworks Help and When They Hinder
- Measuring Security Posture Without Theater
Chapter 20: Securing AI-Assisted Development
- How AI Coding Assistants Actually Work
- Hallucinated Dependencies and Nonexistent Packages
- Vulnerability Patterns in AI-Generated Code
- Prompt Injection in Development Workflows
- AI Tools as Supply-Chain Dependencies
- Securing the AI Development Pipeline
Chapter 21: Autonomous Agents and the Next Frontier
- What Autonomous Agents Can Do Today
- Agent Identity and Authorization
- Terminal and Environment Access
- Repository Interaction and Merge Authority
- Production Deployment by Agents
- Designing Safe Agent Environments
Chapter 22: AI Models, Plugins, and Datasets as Dependencies
- Models as Software Artifacts
- Dataset Provenance and Poisoning
- Plugin and Extension Trust
- Fine-Tuning and Custom Model Supply Chains
- Registry Security for AI Artifacts
Chapter 23: Reference Architectures
- The Small Team: Maximum Security with Minimum Overhead
- The Growing SaaS Company: Scaling Controls with Velocity
- The Large Enterprise: Governance at Scale
- The Regulated Organization: Compliance Without Paralysis
- The Open Source Project: Security Without Central Control
- The Cloud-Native Platform: Supply Chain as a Service
Chapter 24: Assessing and Hardening Your Supply Chain
- Creating an Inventory of Your Supply Chain
- Mapping Trust Boundaries
- Threat Modeling for Supply Chains
- Prioritizing Risks and Quick Wins
- Establishing Security Policies
- Rolling Out Controls Incrementally
Chapter 25: Operations, Monitoring, and Response
- What to Monitor in the Supply Chain
- Detection Patterns and Alerting
- Incident Response for Supply-Chain Compromise
- Recovery, Reroll, and Remediation
- Post-Incident Learning
- Metrics That Matter
Chapter 26: Governance and Organization
- Who Owns the Supply Chain
- Responsibilities Across Teams
- Vulnerability Disclosure and Coordination
- Patching, Exceptions, and Risk Acceptance
- Third-Party and Vendor Risk
- Reporting Up and Measuring Progress
Chapter 27: Tradeoffs and Engineering Decisions
- Security vs. Velocity: Beyond the False Dichotomy
- Automation vs. Human Judgment
- Centralized vs. Distributed Control
- Open Source Contributions and Security Friction
- When Controls Create False Confidence
- Making Tradeoffs Explicit and Sustainable
Chapter 28: The Future of Software Supply-Chain Security
- Increasingly Autonomous Development
- Code Review in the Age of AI
- New Models of Trust and Verification
- Continuous Generation and Continuous Validation
- Regulatory Trajectories
- What Will Last and What Will Change