This work discusses open-source software supply chain attacks and proposes a general taxonomy describing how attackers conduct them. We then provide a list of safeguards to mitigate such attacks. We present our tool "Risk Explorer for Software Supply Chains" to explore such information and we discuss its industrial use-cases.
翻译:本文讨论开源软件供应链攻击,提出了一个描述攻击者如何进行这些攻击的一般分类法。然后我们提供了一些保障措施来减轻这种攻击。我们展示了我们的工具“软件供应链风险探索器”,并讨论了它的工业应用案例。