Journey to the Center of Software Supply Chain Attacks
Piergiorgio Ladisa, Serena Elisa Ponta, Antonino Sabetta, Matías Martínez, Olivier Barais · IEEE Security & Privacy · 2023
This article discusses open source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool Risk Explorer for Software Supply Chains to explore such information, and we discuss its industrial use-cases.