Supply Chain Security
Find open source license risk and unsupported software in your images and workloads, and control which images you deploy
Overview
Supply Chain Security in Sysdig Secure shows the risk that comes with the open source and third-party components you ship. It answers two questions about each component that Sysdig detects:
- Does the license of the component put obligations or restrictions on your organization?
- Does the vendor of the component still support it?
Sysdig takes this data from the same scans that Vulnerability Management uses. You do not install or configure a separate scanner.
Feature Availability
License information and Supply Chain Findings are in Technical Preview.
They are available to all Sysdig Secure SaaS deployments.
Supply Chain Capabilities
| Capability | What it does |
|---|---|
| Supply Chain Findings | Lists the license and end-of-life findings across your pipeline, registry, and runtime resources. |
| License Classification | Explains how Sysdig resolves the license of each package to a category, and which categories raise a finding. |
| Software Lifecycle and End-of-Life Visibility | Explains the lifecycle states, the supported operating systems and runtimes, and the Component Lifecycle policy rule. |
| License Information in the CLI Scanner | Shows licenses in the console output and in the JSON scan result of the CLI Scanner. |
| Supply Chain Policies | Admits only container images with a valid signature into your clusters. |