Software Supply Chain Security Assessment

From XZ to the AUR hijack, the quiet attacks won. We threat-model your pipeline, dependencies, and vendor access โ€” then harden them.

Why this matters: The XZ backdoor nearly shipped to every major Linux distribution from inside a trusted open-source project. The AUR hijack rewrote 400+ packages without changing a version number. Our supply-chain research series covers a decade of these attacks โ€” and the pattern is consistent: the build and distribution layer is trusted by default and attacked accordingly.

What we cover

  • Dependency hygiene: pinning, lockfiles, and update policy
  • Namespace and registry confusion risk in public and private packages
  • Build and release pipeline review โ€” trust, signing, provenance
  • SLSA-aligned hardening of build integrity
  • SBOM gap analysis and third-party component risk
  • Vendor, MSP, and third-party access review โ€” the Kaseya lesson
  • Compromise-response playbook for your pipeline

How we test

1Pipeline threat model

We map how code becomes shipped software: repos, CI, artifact stores, release channels, and every party that can touch them.

2Dependency & registry audit

Manifests, lockfiles, registries, and internal namespaces โ€” looking for confusion risk, takeover risk, and ghost dependencies.

3Build integrity review

Who and what can alter artifacts between commit and deploy; where signing and provenance are missing.

4Tabletop & roadmap

A walkthrough of a realistic compromise with your engineering leads, then a hardening roadmap with quick wins first.

What you get

  • Supply-chain threat model specific to your stack
  • Pipeline hardening roadmap with quick wins first
  • SBOM and attestation readiness checklist
  • Tabletop walkthrough with your engineering leads

The engagement at a glance

๐Ÿ“ž Free scoping call

A short conversation about your environment. You receive a written scope, timeline, and fixed quote โ€” no obligation.

โœ๏ธ Signed authorization

Testing begins only with your written permission and agreed rules of engagement. Always.

โฑ๏ธ Time-boxed delivery

A calendar agreed before we start, with an agreed communication plan while testing runs.

๐Ÿ” Retest included

A verification pass over everything you fix โ€” included in the price, not an add-on.

See the full engagement process โ†’ and how pricing is scoped in our public pricing guide.

Related research from Hmmnm

Common questions

Do you need access to our source code?

Mostly no: manifests, pipeline configuration, and registry setup carry the signal. White-box review is available when you want the deepest pass.

Do you align with SLSA and in-toto?

Yes โ€” we map gaps to SLSA levels and attestation practices so your team has a recognized ladder to climb, not a custom checklist.

How long does an assessment take?

A focused single-pipeline assessment runs about two weeks; multi-product organizations are scoped per pipeline in the scoping call.

Authorization first, always. Testing happens only with your written permission and agreed rules of engagement โ€” the same ethics that govern responsible disclosure on this site.

Want this assessed for your environment?

A short scoping conversation is enough to get a fixed quote. No obligation โ€” a researcher replies.

Start the conversation โ†’