共部门软件供应链报告.pptxVIP

  • 0
  • 0
  • 约3.02万字
  • 约 10页
  • 2026-01-26 发布于湖南
  • 举报

SOFTWARE

SUPPLYCHAIN

PUBLICSECTOR

Thesoftwaresupplychainisavitalcomponentofsuccessfulsoftwaredevelopmentorganizations.However,incidentssuchasthe2020Solarwindsattack,the2021Log4Jvulnerability(Log4Shell),the2024xzbackdoor(CVE-2024-3094),andthe2025“tj-actions/changed-files”supplychainattack(CVE-2025-30066)have

demonstratedhoweasilybackdoorsandbreachesinthesoftwaresupplychaincanbeexploited,impacting

organizationsandindividualsglobally.TheLog4Jvulnerability,inparticular,isnotableduetoitswidespread

deploymentandthestaggering10millionexploitationattemptsperhourreportedjustonemonthafterits

discovery.Justonemonthafterbeingdiscovered,theWallStreetJournalhadidentifiedastaggering10millionexploitationattemptsperhour.1

Organizationsthatimplementrobustsecuresoftwaresupplychaintoolsandpracticesareabletorespondfastertosuchincidents,thankstoincreasedvisibilityandtransparency.Butarisingtideliftsallboatsandasecuresoftwaresupplychainwouldsignificantlymitigatetheriskofsuchattacksbyensuringtheintegrityandauthenticityofsoftwaredependenciesfromdevelopmenttodeployment,preventingmaliciouscodeorunauthorizedmodifications.

TheCloudNativePublicSectorUserGroup2wasformedin2023toserveasahubfordiscussingandadvancingcloudcomputingwithinthepublicsector.Alongsideenumeratingcurrentbestpractices,wearededicated

toimprovingpublicsectorworkflowsandsupplychainsecuritybyadvocatingforthedevelopmentandimplementationofsecureandresilientcloud-nativesoftwarefoundwithinthepublicsector.

Inthiswhitepaper,weaimtoclearlyaddressthecurrentandfuturechallengesofsecuringthepublicsector

softwaresupplychain,andproposelong-term,sustainablesolutionsforusingopensourcetechnologiestomeettheneedsofgovernmentsystems,

您可能关注的文档

文档评论(0)

1亿VIP精品文档

相关文档