Software Supply-Chain Attack Surface
Where attackers can inject malicious code along the build pipeline.
Rendering…
Make it your own.
flowchart LR
Dev[Developer\nworkstation] -->|push| Src[(Source repo)]
Src --> CI[CI pipeline]
CI --> Pkg[Package registry]
CI --> Img[Container registry]
Pkg --> CD[CD pipeline]
Img --> CD
CD --> Prod[Production]
classDef risk fill:#fee2e2,stroke:#991b1b;
A1[Dev creds stolen / typosquat] -.-> Dev
A2[Repo write w/o review] -.-> Src
A3[Compromised build runner] -.-> CI
A4[Dependency confusion] -.-> Pkg
A5[Tampered base image] -.-> Img
A6[Deploy creds leak] -.-> CD
class A1,A2,A3,A4,A5,A6 risk