dido:99_annexes:annex-b-terms-and-definitions:s:software_supply_chain

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

dido:99_annexes:annex-b-terms-and-definitions:s:software_supply_chain [2026/07/13 09:41] – created nick_didodido:99_annexes:annex-b-terms-and-definitions:s:software_supply_chain [2026/07/18 12:33] (current) – external edit 127.0.0.1
Line 5: Line 5:
 ===== Discussion ===== ===== Discussion =====
  
-A Software Supply Chain comprises the people, organizations, processes, tools, services, source materials, dependencies, build inputs, build activities, artefacts, distribution mechanisms, and operational relationships involved in producing and delivering software.+A Software Supply Chain comprises the people, organizations, processes, tools, services, source materials, dependencies, build inputs, build activities, artifacts, distribution mechanisms, and operational relationships involved in producing and delivering software.
  
 The chain begins with the sources and dependencies used to create software and extends through build, test, packaging, signing, storage, distribution, deployment, update, and maintenance activities. The chain begins with the sources and dependencies used to create software and extends through build, test, packaging, signing, storage, distribution, deployment, update, and maintenance activities.
Line 15: Line 15:
 ===== Definition ===== ===== Definition =====
  
-//set of people, organizations, processes, tools, services, sources, dependencies, activities, artefacts, and relationships involved in producing and delivering software//+//set of people, organizations, processes, tools, services, sources, dependencies, activities, artifacts, and relationships involved in producing and delivering software//
  
 ===== Source ===== ===== Source =====
  
-Generalised from software engineering, cybersecurity, procurement, supply-chain risk management, and DevSecOps usage and specialised for the Crucible architecture and operational model.+Generalised from software engineering, cybersecurity, procurement, supply-chain risk management, and DevSecOps usage and specialized for the Crucible architecture and operational model.
  
 ===== Note ===== ===== Note =====
Line 29: Line 29:
 ===== Example ===== ===== Example =====
  
-The Software Supply Chain for a hardened machine image includes the operating-system installation media, package repositories, Packer configuration, Ansible collections, compliance content, build host, signing process, image catalogue, transfer bundle, and target deployment platform.+The Software Supply Chain for a hardened machine image includes the operating-system installation media, package repositories, Packer configuration, Ansible collections, compliance content, build host, signing process, image catalog, transfer bundle, and target deployment platform.
  
 ---- ----
  • dido/99_annexes/annex-b-terms-and-definitions/s/software_supply_chain.1783960873.txt.gz
  • Last modified: 2026/07/13 09:41
  • by nick_dido