Journey to the Center of Software Supply Chain Attacks
arXiv:2304.05200
Abstract
This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool "Risk Explorer for Software Supply Chains" to explore such information and we discuss its industrial use-cases.
arXiv admin note: substantial text overlap with arXiv:2204.04008