Skip to content

#supply-chain

15 approved public terms with this tag.

SBOM Gate is a GitOps term for a release check that requires software bill of materials evidence before promotion. It helps teams, humans, and agents compare declared source state with running systems, then act without pretending a deployment did more than the evidence shows. Source context: OpenGitOps principles.

Signed Image is a GitOps term for a container image with cryptographic proof attached to the artifact. It helps teams, humans, and agents compare declared source state with running systems, then act without pretending a deployment did more than the evidence shows. Source context: OpenGitOps principles.

Supply Chain Abuse Throttle is a security anti-abuse control that slows or blocks suspicious repeated behavior for dependencies, builds, and artifacts. It uses rate limits, reputation signals, and challenge steps so teams can protect public access without a login wall while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Attack Surface is a security exposure model that lists reachable systems, actions, and trust boundaries for dependencies, builds, and artifacts. It uses asset inventory, route discovery, and permission mapping so teams can prioritize risk reduction while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Containment Plan is a security response plan that limits damage after a suspected compromise for dependencies, builds, and artifacts. It uses isolation steps, credential rotation, and communication paths so teams can reduce attacker dwell time while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Data Redaction is a security privacy control that removes sensitive values before data leaves a protected context for dependencies, builds, and artifacts. It uses field rules, hashing, and safe logging so teams can share evidence without leaking secrets while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Detection Rule is a security security analytic that matches suspicious behavior or known indicators for dependencies, builds, and artifacts. It uses logs, thresholds, signatures, and behavioral context so teams can surface actionable alerts while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Evidence Chain is a security audit record that preserves how security evidence was collected and handled for dependencies, builds, and artifacts. It uses timestamps, hashes, owners, and storage controls so teams can support trustworthy investigation while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Forensic Snapshot is a security investigation artifact that captures system state for later review for dependencies, builds, and artifacts. It uses logs, configuration, hashes, and time-bounded data so teams can analyze incidents without changing evidence while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Patch Window is a security remediation schedule that sets when a fix should be applied for dependencies, builds, and artifacts. It uses risk severity, testing needs, and maintenance constraints so teams can repair systems without unnecessary disruption while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Phishing Resistance is a security identity control that reduces success of credential theft attacks for dependencies, builds, and artifacts. It uses passkeys, hardware-backed factors, and origin checks so teams can protect sign-in flows while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Policy is a GitOps term for rules that decide which code, images, dependencies, and sources can be released. It helps teams, humans, and agents compare declared source state with running systems, then act without pretending a deployment did more than the evidence shows. Source context: OpenGitOps principles.

Supply Chain Policy Decision is a security authorization decision that determines whether an action should be allowed for dependencies, builds, and artifacts. It uses identity, resource, context, and policy evaluation so teams can enforce least privilege while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Secret Scanner is a security preventive control that finds credentials before they spread for dependencies, builds, and artifacts. It uses pattern matching, entropy checks, and allowlists so teams can stop accidental key exposure while keeping evidence, reliability, and public-safe operational boundaries clear.

Supply Chain Trust Boundary is a security security boundary that defines where assumptions, identities, or permissions change for dependencies, builds, and artifacts. It uses network edges, service roles, and data classifications so teams can avoid accidental privilege crossing while keeping evidence, reliability, and public-safe operational boundaries clear.