Logo
Submit a request
Sign in
  1. TrustSource Knowledgebase
  2. Software Supply Chain Security

Software Supply Chain Security

...is nowadays a central element of any software solution. Understanding what is used to produce your software solution or product with digital elements, managing dependencies, learning about the security risks and identifying vulnerabilities being introduced by 3rd party components used to build the solution stack. This chapter will address all these aspects, tell more about the solution concepts and introduce, how TrustSource and the TrustSource solutions and tools were designed to support you solving all these challenges.

Risk Management

  • Risk Management Basics
  • Manage Crypto

Manage vulnerabilities

  • Working with the Confidentiality Score
  • The process of vulnerability management
  • Understanding vulnerability management

Export Controls

  • Export Controls Support
  • Setting the scene - define the basics

TrustSource Concepts

  • How do projects and components relate?
  • Understanding the Concept of Approvals
  • Understanding the Concept of Releases
  • Understanding Policies / Allow & Deny Lists
  • Understanding the Concept of Infrastructure Modules

Manage legal compliance

  • Understanding the legal setup determining license suitability
  • Managing Allow- and Deny-Lists
  • Enforce Allow-listing
  • Creating an open source policy
  • Upload and distribute the policy to your organization
  • Invite colleagues and organizational members
See all 9 articles

Manage Outbound - Documentation

  • Outbound artefacts

Frequently asked questions

  • Q: Is it necessary to apply for an OSI-approved license to publish OSS?
  • Q: Are the license terms of a product unrelated to the license terms of OSS?
  • Q: Does the OSS disclaimer remain valid even if OSS is incorporated into the product?
  • Q: Is it possible to use the sample code published in OSS books?
  • Q: Can I use documents or diagrams on OSS for my product under the OSS license?
  • Q: Can I use it within my company, even if commercial use is prohibited?
See all 52 articles
TrustSource Knowledgebase