Software Supply Chain Security Assessment
From XZ to the AUR hijack, the quiet attacks won. We threat-model your pipeline, dependencies, and vendor access โ then harden them.
What we cover
- Dependency hygiene: pinning, lockfiles, and update policy
- Namespace and registry confusion risk in public and private packages
- Build and release pipeline review โ trust, signing, provenance
- SLSA-aligned hardening of build integrity
- SBOM gap analysis and third-party component risk
- Vendor, MSP, and third-party access review โ the Kaseya lesson
- Compromise-response playbook for your pipeline
How we test
We map how code becomes shipped software: repos, CI, artifact stores, release channels, and every party that can touch them.
Manifests, lockfiles, registries, and internal namespaces โ looking for confusion risk, takeover risk, and ghost dependencies.
Who and what can alter artifacts between commit and deploy; where signing and provenance are missing.
A walkthrough of a realistic compromise with your engineering leads, then a hardening roadmap with quick wins first.
What you get
- Supply-chain threat model specific to your stack
- Pipeline hardening roadmap with quick wins first
- SBOM and attestation readiness checklist
- Tabletop walkthrough with your engineering leads
The engagement at a glance
A short conversation about your environment. You receive a written scope, timeline, and fixed quote โ no obligation.
Testing begins only with your written permission and agreed rules of engagement. Always.
A calendar agreed before we start, with an agreed communication plan while testing runs.
A verification pass over everything you fix โ included in the price, not an add-on.
See the full engagement process โ and how pricing is scoped in our public pricing guide.
Related research from Hmmnm
Common questions
Do you need access to our source code?
Mostly no: manifests, pipeline configuration, and registry setup carry the signal. White-box review is available when you want the deepest pass.
Do you align with SLSA and in-toto?
Yes โ we map gaps to SLSA levels and attestation practices so your team has a recognized ladder to climb, not a custom checklist.
How long does an assessment take?
A focused single-pipeline assessment runs about two weeks; multi-product organizations are scoped per pipeline in the scoping call.
Want this assessed for your environment?
A short scoping conversation is enough to get a fixed quote. No obligation โ a researcher replies.
Start the conversation โ