What is Software Supply Chain (Really)? | Sonatype Podcast
What is Software Supply Chain (Really)?
What exactly is a software supply chain, and why is it becoming critical for modern development teams?
In this kickoff episode of Open Source Open Mic, Sonatype’s Andrew Garrett sits down with SVP of Product Tyler Warden to unpack the fundamentals of software supply chains. They explore how today’s applications are built using open source components, how this model compares to traditional supply chains, and the unique risks it introduces.
The conversation digs into key topics like the difference between vulnerabilities and open source malware, the growing influence of AI on software development, and the shared responsibility across Dev, Sec, and Ops teams. You’ll also hear practical strategies for improving DevSecOps practices and navigating increasing regulatory pressure.
Whether you’re a developer, security leader, or engineering executive, this episode offers actionable insights to help you better understand and secure your software supply chain.
Transcript
0:01: OK.
0:02: So we are live.
0:07: Hello everyone, and welcome to this episode of Open Source Open Mic.
0:12: This is our first episode of hopefully many in the series, where we will dive into trending topics around.
0:20: Open source security, software composition analysis, and all things security.
0:26: My name is Andrew Garrett, and I am a product marketing manager here at Sonatype, and I am pleased to be joined today by Tyler Warden.
0:37: And Tyler is our SVP of product here at Sonatype.
0:43: He's based in Atlanta, Georgia.
0:47: Tyler, anything you would like to say to introduce yourself to our viewers today?
0:54: Just thanks for having me here, Andrew.
0:57: I'm looking forward to the discussion today and thanks everybody for taking some time to listen to us.
1:02: Awesome.
1:03: Well, today we're gonna dive into the topic of what is a software supply chain.
1:09: This is a term we hear a lot in the world of security, so, Tyler, why don't you kick us off?
1:15: What is a software supply chain and how is it similar or maybe different to a traditional supply chain?
1:22: The supply chain is all the source material or raw material or components that you bring together to go into and help make the thing that you want to make.
1:38: Let's anchor on a physical supply chain.
1:41: The most famous example is a car.
1:46: In order to make a car, we need tires and brakes and rotors and metal and spark plugs and windshield wipers.
1:56: When a car manufacturer is making a car, some things they make themselves, some they buy, some they source.
2:04: Just like a physical supply chain, the software supply chain is about the components, dependencies, or outside things you bring into your product, and the vast majority of those are open source software components.
2:26: About 85 to 90% of enterprise software by lines of code is actually open source.
2:34: Why is that?
2:40: Because why would a car manufacturer make a spark plug when they could source one?
2:44: However, one significant difference is that with open source, you're sourcing from the internet and getting random pieces of software.
3:03: I don’t know if the component is trustworthy.
4:11: If they are, we can help you make that decision. If they are not, we can help you see that and make a better decision.
4:31: There are many similarities in terms of the foundation, but the application from a physical good to an open-source set of bits is where important differences arise.
4:48: So as a developer, what are some of the components in the software supply chain for developers?
5:42: If you want to switch to a food metaphor, if I'm a developer, I'm going to buy a sandwich, but in that sandwich is lettuce and meat and bread and cheese, and that meat has its own journey to get to my sandwich.
6:11: I may be buying the sandwich, but I, as the developer, will be held responsible for everything inside that sandwich, not just the sandwich itself.
7:20: Let’s discuss where things can go wrong in the software supply chain.
7:34: Vulnerabilities are unintentional flaws, while open source malware is intentionally created by bad actors to compromise systems.
8:32: It was an unintentional mistake that led to vulnerabilities such as the React vulnerability.
9:40: Malicious actors might exploit software supply chains through open-source malware, which poses a significant threat.
10:27: We should think about protecting ourselves against both unintentional vulnerabilities and malware protection, which is critical.
10:51: So are we putting too much trust in open source sometimes?
11:25: Open source is an amazing force for good, but we must have proper guardrails and adopt a “trust but verify” approach when using it.
12:23: In practice, ownership of software supply chain security is shared across teams: Developers are accountable for the code they build, Security teams provide oversight and validation, and DevOps enables secure processes.
14:35: Regulations are helping enforce or shine a light on some best practices that should happen.
20:05: Key recommendations include:
- Choose fewer, better suppliers.
- Maintain visibility into all dependencies (direct and transitive).
- Don’t pass defects downstream.
21:32: Every CISO should track mean time to remediate.
22:14: If you're not already subscribed to the Sonatype YouTube channel, we hope you will.