software-supply-chain-failures — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited software-supply-chain-failures (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A03:2025 is the #1 community-voted concern and the highest-risk category by exploit score in the entire OWASP Top 10:2025, despite having only 6 CWEs and limited test data:
| Metric | Value |
|---|---|
| OWASP Rank | #3 (new — expands A06:2021 "Vulnerable & Outdated Components") |
| Average Incidence | 5.72% |
| Avg Exploit Score | 8.17 (highest of any category) |
| Avg Impact Score | 5.23 (highest of any category) |
| Key CWEs | CWE-1104, CWE-1395, CWE-1329 |
Key CWEs:
Supply chain failures span the full lifecycle — from sourcing packages to building, distributing, and deploying them:
Python-specific surface: Flask alone pulls 7+ transitive packages (Jinja2, Werkzeug, MarkupSafe, itsdangerous, click, blinker, packaging). FastAPI pulls Starlette + Pydantic + their dependencies. Every transitive package is an attack surface.
pip-audit (recommended — scans against OSV + PyPI Advisory DB)# Install
pip install pip-audit
# Scan current environment
pip-audit
# Scan a requirements file
pip-audit -r requirements.txt
# Output JSON for CI
pip-audit -r requirements.txt -f json -o audit-results.json
# Fix automatically where possible
pip-audit --fixsafety (scans against Safety DB / PyUp)pip install safety
# Basic scan
safety check
# Scan requirements file
safety check -r requirements.txt
# Full JSON output
safety check --jsonosv-scanner (Google OSV — broadest database)# Install via Go or download binary
go install github.com/google/osv-scanner/cmd/osv-scanner@latest
# Scan a project directory
osv-scanner --lockfile=requirements.txt .Trivy (containers + filesystem)# Scan Python project
trivy fs --scanners vuln .
# Scan a Docker image
trivy image myapp:latestCI/CD Integration: Runpip-audit+safetyon every PR. Fail the build on HIGH/CRITICAL severity findings. Seereferences/ci-cd-templates.mdfor GitHub Actions and GitLab CI examples.
An SBOM (Software Bill of Materials) is now a compliance requirement (US Executive Order 14028) and an operational necessity.
cyclonedx-pypip install cyclonedx-bom
# Generate CycloneDX SBOM from current environment
cyclonedx-py environment -o sbom.json --format json
# From a requirements file
cyclonedx-py requirements requirements.txt -o sbom.json --format json
# From poetry
cyclonedx-py poetry -o sbom.jsonpip-licenses for license compliancepip install pip-licenses
pip-licenses --format=json --output-file=licenses.jsonSBOM should include:
requirements.txt# BAD — unpinned, vulnerable to substitution attacks
flask==3.0.0
# GOOD — hash-pinned, tamper-evident
flask==3.0.0 \
--hash=sha256:34a14a9e9ea... \
--hash=sha256:a9b5cf1a...Generate hash-pinned requirements:
pip install pip-tools
pip-compile --generate-hashes requirements.in -o requirements.txt| Tool | Lockfile | Command |
|---|---|---|
| Poetry | poetry.lock | poetry install --no-root |
| uv | uv.lock | uv sync |
| pip-tools | requirements.txt (compiled) | pip-sync requirements.txt |
| Pipenv | Pipfile.lock | pipenv install --ignore-pipfile |
Critical checks:
requirements.txtpip install pipdeptree
pipdeptree --json-tree > deptree.json
# Find who requires a specific package
pipdeptree --reverse --packages flask# guarddog — detects malicious behavior in packages
pip install guarddog
guarddog pypi scan flask
guarddog pypi verify flask 3.0.0# Bandit catches these automatically:
import sys
sys.path.insert(0, '/untrusted/path') # CWE-426: Untrusted Search Path
sys.path.append('/local/unverified') # Same riskbandit -r . -t B322,B323,B411 # sys.path manipulation checksUnhardened pipelines are a primary supply chain vector (SolarWinds attack model).
| Control | Implementation |
|---|---|
| MFA on pipeline auth | Require OIDC tokens, not static secrets |
| Signed builds | sigstore / cosign for container images |
| Tamper-evident logs | Immutable audit logs (e.g. Rekor) |
| Dependency pinning | Pin action versions by SHA, not tag |
| Least-privilege | Separate read/write tokens per stage |
| Staged rollouts | Canary deploy before full rollout |
# BAD — tag can be moved by attacker
- uses: actions/checkout@v4
# GOOD — immutable SHA
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683# Generate SLSA provenance with slsa-verifier
pip install slsa-verifier
slsa-verifier verify-artifact mypackage.tar.gz \
--provenance-path provenance.json \
--source-uri github.com/myorg/myrepo| Framework | Direct deps | Key transitives to monitor |
|---|---|---|
| Flask | flask, flask-login, flask-wtf, sqlalchemy | Jinja2, Werkzeug, MarkupSafe, itsdangerous |
| FastAPI | fastapi, uvicorn, sqlalchemy, pydantic | Starlette, anyio, httpx, h11 |
pip install bandit
# Full scan with supply-chain relevant rules
bandit -r . -t B301,B302,B303,B324,B411,B412 --format json -o bandit-report.jsonKey Bandit rules for supply chain:
B301 — pickle usage (deserialization risk)B302 — marshal (similar risk)B411 — xmlrpc importsB412 — httpoxy detection# Use pip-audit with strict mode
pip-audit --strict -r requirements.txt
# guarddog behavior analysis
guarddog pypi scan <package>| Finding | Severity | Action |
|---|---|---|
| CVE with CVSS ≥ 9.0 in direct dep | Critical | Patch immediately, block deploy |
| CVE with CVSS 7.0–8.9 in direct dep | High | Patch within 48h |
| CVE in transitive dep only | Medium | Patch within 2 weeks |
| Unpinned dependency | Medium | Add to lockfile in next sprint |
| No SBOM | Medium | Generate and automate in CI |
Missing --hash on requirements | Low | Migrate to lockfile tool |
| Outdated lockfile (>30 days) | Low | Regenerate + review changes |
| No automated dep update bot | Low | Enable Dependabot/Renovate |
[ ] pip-audit and safety check passing in CI (no HIGH/CRITICAL)
[ ] All dependencies pinned in lockfile (poetry.lock / uv.lock)
[ ] Lockfile committed to source control and used in CI installs
[ ] SBOM generated (cyclonedx-py) and stored as CI artifact
[ ] Dependabot or Renovate Bot enabled on repository
[ ] GitHub Actions pinned by commit SHA
[ ] No sys.path.insert() / sys.path.append() on unverified paths
[ ] SLSA Level 2+ for published packages
[ ] Weekly lockfile refresh scheduledreferences/ci-cd-templates.md — GitHub Actions + GitLab CI pipeline templates withpip-audit, safety, SBOM generation, and SLSA provenance steps
references/cwe-mapping.md — Full CWE-to-detection-tool mapping for audit reporting~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.