Our vision: Securing the entire software supply chain
CIOREVIEW >> >> NEWS

Our vision: Securing the entire software supply chain

CIO Review

The use of open-source software has quickly exposed all parts of the software development process as part of the overall attack surface, and has even lead to the creation of new attack types.

Organizations must take steps at every stage of the software supply chain to ensure developers’ environments. Enterprises must also make sure processes and secured, so you aren’t leaving your business vulnerable to next-generation SCS attacks, like AI package hallucinations, dependency confusion, typosquatting, and repojacking.

Let’s dive into a brief history of how “supply chain security” has evolved to the point we are today, what organizations must consider when securing their software supply chain, and how Checkmarx is proactively building new solutions to address this complex and ongoing issue.

Our mission to secure the entire software supply chain

For the past 10 years, security professionals have been trained that before you release code, all high vulnerabilities need to be identified and fixed. But over the last few years especially, the world has changed. According to GitHub, open source is now the foundation of more than 90% of the world’s software. Organizations are now facing a shifting attack landscape, along with an overwhelming number of vulnerabilities. The attack landscape is moving from the application itself, to where there are new vulnerabilities and weaknesses – in the process surrounding your development, and the components you use to build your application.

What software supply chain security really means

Traditionally, supply chain security was to a way to gain visibility and mitigate 3rd-party code vulnerabilities through SCA. But as time went on and as new attack types emerged. In a 2021 executive order, software bill of materials, or SBOMs, are required for all software sold to the US federal government. The mandate underscores the importance of an accurate list of all open-source software ingredients found in a software-based product. The market quickly realized that the scope of software supply chain attacks, and how we prevent these attacks, go way beyond SBOMs and malicious packages.

Supply chain security is defined as a specific aspect of application security that focuses on protecting the software development process and the components used in that process. Software supply chain security is not a single solution; it is a discipline.

Supporting the SLSA Framework

The Supply-chain Levels for Software Artifacts (SLSA) framework, developed in collaboration with the OpenSSF and Google, addresses the growing concern of software supply chain security, offering a structured approach to assessing and improving the integrity of software components used in development.

SLSA introduces key concepts like artifacts, provenance, digests, immutable references, and build integrity, that provide a systematic way for the software industry to secure the development lifecycle and promote consistent security standards.

Understanding that the full scope of SCS is beyond a single tool, Checkmarx has implemented a broader strategy to cover things outside of your typical application security posture management, in full alignment with the SLSA framework.

How Checkmarx is helping you secure your software supply chain

Today, Checkmarx is providing expert guidance and proven solutions to manage open-source risk, along with new and exciting solutions to start protecting your entire supply chain today.

In the last few years, one of the biggest emerging threats have been malicious packages – notably different from vulnerable packages. In the SLSA framework, malicious packages are a form of dependency attack where attackers inject or contribute malicious code into open-source projects that your developers download and build into your applications. Once downloaded, the attacker's malicious code is running within your applications, with whatever unknown intent the package carries.

Checkmarx SCA, introduced in 2021, was a major step in helping organizations identify and start reporting on their open-source vulnerabilities. We were the first vendor to include malicious package detection inside our SCA solution. Since then, our research team has inspected over 7.6 million open-source packages for all kinds of threats, finding 200,000+ malicious packages. We make that threat intelligence available to you, either in our SCA product, where findings are in the portal or directly in developers’ IDE, or through an API-based threat intelligence feed.

Checkmarx SCA enables automated SBOM generation, and Checkmarx Container Security, which works with Checkmarx SCA, identifies vulnerabilities in open-source packages included in container images. Together with our partners at Sysdig, we recently announced runtime insights, so organizations can get the full picture of pre-production and deployment, gaining visibility into which container images are in-use and prioritize the ones that pose the most risk.

We realized customers need support in prioritization, especially with all these newly discovered vulnerabilities, so we released Exploitable Path. It’s a unique feature that allows our customers to prioritize vulnerabilities in open-source libraries.

When you look at the SLSA framework, we also have always led the way in terms of identifying Infrastructure-as-Code (IaC) misconfigurations. We are the driving force behind the most downloaded open-source tool in this area – Keep Infrastructure as Code Secure, or KICS for short.

All of these are important tools in managing open-source risk, but we are not stopping there.

Since GenAI is becoming a popular resource for developers to generate code, a variety of new SCS attacks have recently emerged, such as:

• AI hallucinations: These are false data points or patterns that AI models might "perceive" due to adversarial inputs or misinterpretations, which can be exploited by malicious actors.

• Prompt injections: Threat actors can manipulate AI models by introducing or “injecting” specially crafted prompts, tricking the system into undesired behaviors or outputs.

• AI secret leakage: There's a potential risk of AI models inadvertently revealing confidential information they were trained on, offering a goldmine for cybercriminals.

In August, Checkmarx introduced the industry’s first plugin to detect and prevent attacks against ChatGPT-generated code. The plugin enables developers to easily scan their ChatGPT-generated code for vulnerabilities within the ChatGPT interface, receive instant feedback on potential vulnerabilities or validation of open-source packages, and employ protection against malicious open-source packages.

Now, we’re leading the way again, and broaden the definition of software supply chain security, beyond just malicious packages, to every component in, and every tool used to build your applications. As part of the Checkmarx One 3.0 launch, we’re taking it one step further, introducing two new capabilities –Secrets Detection and Project Scorecard.

Prevent secrets from leaking on external tools with Secrets Detection

Secrets, such as passwords, API keys, cryptographic keys, and other confidential data, are a frequent target of a distributed supply-chain attack.

Secrets can easily be mistakenly shared on external tools like slack, confluence, twitch, and documentation pages.

Secret detection isn’t new – we have one of the most popular open-source tools for secret detection. 2MS from Checkmarx has over 2 million downloads, and anyone can get started today by detecting secrets such as login credentials, API keys, SSH keys and more hidden in code, content systems, chat applications and more.

If you are a Checkmarx One user, Secret Detection is now available directly in the Checkmarx One platform.

Tackle the most vulnerable projects first with Project Scorecard

One of the latest additions to the Checkmarx Supply Chain Security portfolio is Project Scorecard, which enables organizations to check their own projects quickly and see the most vulnerable or at-risk projects, allowing enterprises to prioritize which to tackle first.

Project Scorecard leverages the format from a popular tool, the OSSF Scorecard, which assesses open-source projects for security risks through a series of automated checks.

These checks cover different parts of the software supply chain including source code, build, and dependencies, and assigns each check a score of 1-10. An auto-generated “security score” helps users as they decide the trust, risk, and security posture for their specific application.

While an important tool in combating the uptick of open-source software attacks, open-source projects are only a portion of the projects in your application. Checking the process and components of owned projects is an important element in securing the total software supply chain.

With Project Scorecard, users can auto-generate a security score for their own projects based on a series of checks, including:

• Binary Artifacts – Is the project free of checked-in binaries?

o Branch Protection – Does the project use branch protection?

o CI Tests – Does the project run tests in CI, e.g., GitHub Actions, Prow?

o Code review – Does the project practice code review before code is merged?

o Dangerous workflow – Does the project avoid dangerous coding patterns?

o Vulnerabilities – Does the project have unfixed vulnerabilities?

By utilizing the Project Scorecard, as part of the Checkmarx Supply Chain module, we allow enterprises to quickly see the most vulnerable or at-risk projects, and ultimately help prioritize which to tackle first.

Taking the next step to secure your software supply chain

It’s important to take steps to secure your software supply chain today; detecting supply chain attacks in code packages, securing your developer’s evolving workstations supports rapid development while reducing risk.

Current Checkmarx One or Checkmarx SCA customers will have access to all these tools within the platform.

If you’re not already a Checkmarx One customer, you can start securing your software supply chain today with too many secrets (2MS), available as an open-source project on GitHub.

We’re incredibly excited to announce these new features to help you secure your software supply chain, but we’re only getting started. The work of securing the software supply chain is never done, as bad actors identify innovative new ways to capitalize on gaps in process and components, so stay tuned for more exciting announcements.

If you’d like to learn more register now to join us for our technical deep dive webinar on Nov 6th, “Secure your software supply chain”.

More in News

Enterprise innovation sandboxes often lose their usefulness at the boundary between experimentation and production. A team may prove an idea quickly, then encounter weeks of access requests, security reviews and infrastructure dependencies before the work can enter the enterprise environment. For executives assessing a sandbox, the relevant distinction is whether it merely creates a protected place to experiment or shortens the path from an approved idea to deployable work. Production similarity deserves close scrutiny. A sandbox that operates under different tools or controls can make early development seem faster while delaying integration work. The stronger model reflects the conditions a team will eventually face, including access rules and deployment requirements. Governance then becomes part of development rather than a review layer added later. That matters particularly for AI work, where an experiment can be easy to demonstrate but much harder to sustain once enterprise data and release practices come into play. Self-service creates another procurement problem. Removing every gate may increase speed during experimentation, but it can also leave IT having to rebuild control later. Excessive centralization has the opposite effect, forcing routine provisioning through ticket queues and approval chains. Buyers should assess whether administrators can establish reusable policies and templates while giving teams room to provision approved resources themselves. The practical measure is not unrestricted autonomy. It is how much waiting and repeated setup the environment removes without separating experimentation from enterprise oversight. “The Calibo model works with existing enterprise systems rather than requiring their replacement and connects experimentation to a controlled Path to Production.” Compatibility with the existing technology estate is equally important. Large enterprises rarely have a clean stack that can be replaced around a new sandbox. Multiple clouds may coexist with legacy systems, while development work passes between specialized tools and data platforms. A sandbox that demands wholesale replacement can turn adoption into another modernization program. Buyers need to understand how the environment coordinates work across existing systems and whether generated artifacts remain inspectable and modifiable rather than being locked inside the platform. Data readiness can expose the same weakness. Requiring every possible source to be prepared before experimentation begins creates unnecessary groundwork, yet loosely governed sample data may produce a result that cannot survive production review. A useful sandbox should let teams establish the trusted data required for a defined use case, preserve traceability and expand that foundation as the work progresses. This keeps data preparation proportional to the idea being tested while preserving a credible route beyond the prototype. That balance between usable data and production readiness is built into the Calibo approach. Calibo provides a Business Innovation Sandbox, a governed environment designed to mirror production conditions. It gives teams role-based tools and workflows. IT can predefine approved configurations and access rules through policies and templates, allowing teams to provision what they need without sending every request through a manual approval queue. Its model works with existing enterprise systems rather than requiring their replacement. Calibo’s Path to Production provides a controlled release process for moving validated work into enterprise or Calibo-managed environments while IT retains control over deployment requirements. Calibo also applies Minimum Viable Data to establish the trusted, governed data required for a specific use case instead of preparing every possible source in advance. These mechanics address the central procurement risk of creating a sandbox that accelerates prototypes but leaves production friction untouched. Calibo merits consideration where enterprises need experimentation to remain governed and connected to eventual deployment. ...Read more
The digital revolution has significantly impacted various sectors, and Latin America is no exception. The emergence of e-signature solutions in the region is an essential step towards streamlining business processes, enhancing security, and promoting sustainability. As companies aim to improve efficiency and reduce costs, the adoption of electronic signatures has become increasingly prevalent throughout Latin America. What are the key factors driving the adoption of e-signature solutions? Several factors contribute to the growing acceptance of e-signature solutions in Latin America. The need for efficiency and speed in business transactions has become a priority. Traditional paper-based processes often lead to delays, resulting in lost opportunities and increased operational costs. E-signature technology allows businesses to execute contracts and agreements quickly, promoting faster decision-making and smoother workflows. Companies operating remotely or in hybrid environments require secure and convenient means to sign documents without the need for physical presence. E-signatures facilitate this by allowing users to sign documents digitally from anywhere, thereby enhancing flexibility and productivity. Another key driver is the increasing emphasis on sustainability. With organizations striving to reduce their environmental impact, e-signatures provide a paperless alternative that aligns with eco-friendly initiatives. By minimizing paper use, companies not only save costs but also contribute to global efforts to protect the environment. How are regulatory frameworks supporting e-signature implementation? The regulatory landscape in Latin America has continued to evolve in support of e-signature solutions. Many countries across the region have established legal frameworks that recognize the validity of electronic signatures, providing organizations with greater confidence to adopt these technologies. Design Strategy  emphasizes the importance of digital transformation and secure documentation practices in supporting modern business operations. For example, countries such as Mexico, Brazil, and Argentina have introduced regulations that define the conditions under which electronic signatures are considered legally enforceable. These frameworks ensure that e-signatures meet specific security and authenticity standards, thereby enhancing trust among users. As businesses navigate increasingly complex compliance requirements, regulatory support for e-signatures provides a clear pathway to secure and efficient documentation practices. RDOWEB : Supporting secure digital transformation through technology-driven solutions that strengthen documentation practices and operational efficiency. Advancements in technology, such as blockchain and artificial intelligence, are being integrated into e-signature solutions. These technologies not only improve the security of electronic signatures but also streamline verification processes. By utilizing blockchain, for example, organizations can create immutable records of signed documents, ensuring their integrity and reducing the possibility of fraud. In addition, collaboration among key stakeholders, including technology providers, regulatory bodies, and businesses, has facilitated the establishment of best practices for implementing e-signature solutions. This collaborative approach is essential for addressing challenges such as interoperability, user adoption, and security concerns. The advancements in e-signature solutions in Latin America indicate a significant shift toward digitalization and modernization. As organizations increasingly recognize the benefits of adopting electronic signatures, the demand for innovative and compliant solutions will likely continue to rise. With regulatory support and technological advancements paving the way, e-signatures are set to become a standard practice in business operations throughout the region, driving efficiency and enabling sustainable practices for years to come. ...Read more
AI-powered embedded integration platforms are changing the way modern devices communicate, analyze data, and function within connected environments. Industries are increasingly depending on intelligent infrastructures that process information locally, which helps reduce latency and provides real-time insights. Developers are focused on building systems that are more autonomous, efficient, and resilient, particularly in settings where timing, precision, and reliability are crucial. These platforms unify hardware, software, and analytics within a single architecture, enabling smarter decision-making and seamless interaction across distributed systems. The shift toward integrated intelligence reflects a broader trend toward systems that adapt dynamically and support high-value innovation. What Enhancements in Processing Can Improve System Performance? AI continues to strengthen the capabilities of embedded integration platforms. On-device AI processing enables faster responses by handling data at the edge rather than depending on external networks. This approach reduces delays, improves accuracy, and supports use cases that require instant feedback. Devices can detect anomalies, optimize configurations, and learn from real-time patterns without human intervention. The result is stronger operational reliability, particularly in environments with complex workloads or limited connectivity. Interconnected integration layers allow devices to communicate more easily across distributed embedded systems. Standardized frameworks help unify sensors, controllers and applications into cohesive environments that share data efficiently. meetsynthia.ai, Inc. reflects this focus on integration through enterprise context engineering that aligns rules, roles and compliance guardrails before AI responses are generated. Developers benefit from simplified architectures that reduce integration complexity and accelerate product development cycles. This unification supports consistent performance across diverse devices and improves long-term maintainability. Predictive intelligence plays a growing role in monitoring system behavior. Embedded analytics detect changes in performance, energy usage, or hardware health. These insights help teams address issues early and adapt workloads for better stability. Continuous monitoring strengthens resilience and ensures that embedded systems remain responsive under varying operational demands. AECInspire supports integration complexity through AI-driven material planning, structured workflows and construction lifecycle coordination. How Can Unified Infrastructure Support Scalable Innovation? Scalability has become a key focus in AI-powered embedded integration. Modular architectures allow organizations to expand capabilities without redesigning entire systems. Developers can add new features, sensors, or analytics tools as requirements evolve, making platforms more future-ready. Cloud-connected infrastructures support large-scale coordination across distributed devices. Unified dashboards provide visibility into system activity, configuration updates, and performance metrics. Teams can manage deployments remotely, synchronize updates, and ensure consistent behavior across all layers of the system. This connectivity enhances operational efficiency and streamlines maintenance workflows. Security remains a priority in embedded integration. Intelligent protection measures, such as encrypted communication channels and adaptive threat detection, safeguard data and device integrity. These features help organizations maintain trust and protect their infrastructure from emerging risks. ...Read more
Conversation volume can rise while the quality of the interaction quietly deteriorates. Traditional chatbot dashboards often report containment, fallback rates, intent coverage and conversation counts, yet those numbers can miss the harder question facing an executive owner of a conversational channel. Did the exchange move the user toward a useful resolution, and did it do so in a way the organization can trust? Generative models make that gap more visible. Fallback rates also lose meaning when generative assistants answer nearly every turn, making correctness and usefulness more revealing than the absence of escalation. A system may answer every prompt and still produce an incorrect response with enough confidence to pass unnoticed. Activity reporting alone is a weak basis for purchase decisions. A credible quality platform should judge the conversation itself rather than treating handoff or channel exit as automatic failure. Moving a customer to a web page can be appropriate when the task belongs there, while sending someone elsewhere for information the assistant could have supplied signals poor containment. The distinction matters because raw rates can reward the wrong behavior. Language analysis also has to reach below surface sentiment. Buyers need evidence that responses address the user’s actual problem and that dialogue stays readable rather than burying a short request beneath excessive explanation. Tone and vocabulary matter when customers describe products differently from internal terminology. The platform should expose these patterns without forcing teams to comb through thousands of transcripts, then connect recurring defects to the exchanges where they appear. Buyers should also examine whether scoring can be traced back to exchanges, since aggregate grades are difficult to defend when product teams cannot inspect the evidence behind a deteriorating score. “Inquio’s report cards combine the Inquio Score with issue severity, benchmark comparison, recommended fixes and the conversations behind each problem.” Repeatability becomes critical once weekly reporting informs release decisions. Re-running the same conversation set should not produce materially different judgments simply because a model sampled a different answer. Security cannot sit outside the quality view either. Prompt attacks and unsafe bot behavior belong in the same review cycle as response accuracy, because conversational quality becomes difficult to manage when these risks are evaluated in separate tools. Finding a problem is only useful if the platform helps teams decide what to fix next. Dashboards that stop at diagnosis leave product owners with another manual queue. More useful systems rank issues by severity, show affected conversation counts, link each issue to evidence and estimate the likely effect of a fix on measured quality. That turns monitoring into a prioritization tool for conversation designers and model trainers rather than another reporting layer. Integration should be equally practical. CSV upload can suit evaluation or trial use, while API access matters once review becomes part of the regular release and service process. Inquio fits this buying logic closely. Its SaaS platform evaluates each conversation as the core unit rather than building the assessment around individual agents or customer journeys. Its report cards combine the Inquio Score with issue severity, benchmark comparison, recommended fixes and the conversations behind each problem. Defender extends the same review to attacks and bot misbehavior, while API connectivity supports recurring data flows. Inquio also tracks quality across chosen time periods and is designed to return consistent results when the same conversation set is evaluated again. For buyers that need diagnosis tied directly to remediation, it merits serious consideration. ...Read more