Securing the software supply chain for containers: practices and challenges in a cloud-native landscape for a global observatory
Uğur Yılmaz, Piers Harding · 2024
In the rapidly evolving landscape of software development the adoption of containerization has transformed the software supply chain. Containers encapsulate software components, ensuring consistency across multiple development, testing, and production environments. They foster agility and scalability by enabling microservices architecture and DevOps practices. The recent increase in cyberattacks targeting research institutes makes it critical to have a secure supply chain for containers and their orchestration. This paper delves into the integration of containers within the software supply chain, examining best practices and challenges in orchestration, security, and continuous integration and delivery (CI/CD) and distribution. We focus on how containers are secured from build stage, verified and distributed securely and validated in production, while also exploring the implications for dependency management and obsolescence in modern cloud-native infrastructures. Our analysis provides insights into maximizing the benefits of containerization to streamline development pipelines and enhance software supply chain resilience.