<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Supply Chain</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain/</link><description>Recent content on Supply Chain</description><language>en</language><lastBuildDate>Thu, 01 Oct 2026 11:53:24 +0100</lastBuildDate><image><url> https://docs.sysdig.com/icons/sysdig-horizontal.png</url><title>Supply Chain</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain/</link><description>Sysdig logo</description></image><item><title>Supply Chain - Overview</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain/#overview</link><description>Supply Chain Security in Sysdig Secure shows the risk that comes with the open source and third-party components you ship. It answers two questions about each component that Sysdig detects:</description><content:encoded><![CDATA[<p>Supply Chain Security in Sysdig Secure shows the risk that comes with the open source and third-party components you ship. It answers two questions about each component that Sysdig detects:</p>

<ul>

<li>Does the license of the component put obligations or restrictions on your organization?</li>

<li>Does the vendor of the component still support it?</li>
</ul>


<p>Sysdig takes this data from the same scans that Vulnerability Management uses. You do not install or configure a separate scanner.</p>
<div class='row alert d-flex infobox infobox--note'>
  <div class="ps-0 col-md-auto">
  <i class='fas fa-info-circle fa-lg'></i>
  </div>
  <div class="ps-0 col infobox__contents">
  
<p class="infobox__title">Feature Availability</p>
  
<p>License information and Supply Chain Findings are in <strong>Technical Preview</strong>.</p>

<p>They are available to all Sysdig Secure SaaS deployments.</p>
  </div>
</div>]]></content:encoded><guid isPermaLink="false">Overview</guid></item><item><title>Supply Chain - Supply Chain Capabilities</title><link>https://docs.sysdig.com/en/sysdig-secure/supply-chain/#supply-chain-capabilities</link><description>Capability What it does Supply Chain Findings Lists the license and end-of-life findings across your pipeline, registry, and runtime resources. License Classification Explains how Sysdig resolves the license of each package to a category, and which categories raise a finding. Software Lifecycle and End-of-Life Visibility Explains the lifecycle states, the supported operating systems and runtimes, and the Component Lifecycle policy rule. License Information in the CLI Scanner Shows licenses in the console output and in the JSON scan result of the CLI Scanner. Supply Chain Policies Admits only container images with a valid signature into your clusters.</description><content:encoded><![CDATA[<table>
	<thead>
			<tr>
					<th style="text-align: left">Capability</th>
					<th style="text-align: left">What it does</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td style="text-align: left"><a href="/en/sysdig-secure/supply-chain-findings/">Supply Chain Findings</a></td>
					<td style="text-align: left">Lists the license and end-of-life findings across your pipeline, registry, and runtime resources.</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/en/sysdig-secure/license-classification/">License Classification</a></td>
					<td style="text-align: left">Explains how Sysdig resolves the license of each package to a category, and which categories raise a finding.</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/en/sysdig-secure/vm-lifecycle-visibility/">Software Lifecycle and End-of-Life Visibility</a></td>
					<td style="text-align: left">Explains the lifecycle states, the supported operating systems and runtimes, and the Component Lifecycle policy rule.</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/en/sysdig-secure/cli-scanner-vm-mode/#license-information">License Information in the CLI Scanner</a></td>
					<td style="text-align: left">Shows licenses in the console output and in the JSON scan result of the CLI Scanner.</td>
			</tr>
			<tr>
					<td style="text-align: left"><a href="/en/docs/sysdig-secure/policies/supply_chain/">Supply Chain Policies</a></td>
					<td style="text-align: left">Admits only container images with a valid signature into your clusters.</td>
			</tr>
	</tbody>
</table>]]></content:encoded><guid isPermaLink="false">Supply Chain Capabilities</guid></item></channel></rss>