Software Supply Chain Failures

Expert guidance on detecting, assessing, and remediating Software Supply Chain Failures (OWASP A03:2025) in Python applications — the highest-exploit-score category in the 2025 OWASP Top 10. Use this skill whenever the user mentions dependency scanning, vulnerable packages, SBOMs, pip-audit, safety check, lockfile integrity, hash pinning, transitive dependencies, CI/CD pipeline security, compromised packages, supply chain attacks (SolarWinds, Log4Shell, typosquatting), or requests a security review of requirements.txt / pyproject.toml. Also trigger for any question about CWE-1104, CWE-1395, or CWE-1329.

scholarly360 Updated

File contents

scholarly360/owasp-top10-web-skills/tree/main/skills/software-supply-chain-failures commit b23e032f7e

Frequently asked questions

npx skillmds@latest add scholarly360/software-supply-chain-failures