OWASP A03 supply chains: protect builds and releases as well as dependencies
Review component versions, build credentials, artifact provenance and recovery paths.
Contents of this article
Follow software into production
OWASP A03:2025 addresses failures in building, distributing and updating software. Dependencies are one part; tools, CI plugins, registries and release accounts also affect production. A clean CVE scan does not establish end-to-end trust.
Track what the artifact contains
Track direct and transitive dependencies, base images and runtimes against release artifacts. Route updates through source, change and compatibility checks. Plan replacement for abandoned or unupgradable components rather than permanent exceptions.
Separate build and production authority
Provide only required credentials to builds and keep production secrets out of logs, layers and public artifacts. Make releases reviewable and traceable and verify artifact integrity and origin. External contributions and test jobs should not inherit production publishing rights.
Recover to a trusted release
Identify affected artifacts and deployments before restoring a verified release. Revoke and rotate compromised publishing credentials. CDN refresh updates delivery but does not establish file safety; check whether old artifacts remain downloadable.
References
OWASP Top 10 2025: Software Supply Chain Failures
