# What is Software Supply Chain Security? | Dev Interrupted Powered by LinearB

> You may have heard of the supply chain, but what about the software supply chain? What is it and how do you keep it secure?

_This is a markdown rendering of a live HTML page on linearb.io, generated for AI/LLM consumption — it is not a markdown-only site. To get the full HTML page instead, request this URL with an explicit `Accept: text/html` header (no wildcard, no markdown preference)._

[Blog](https://linearb.io/dev-interrupted/blog)

/

What is Software Supply Chain Security?

# What is Software Supply Chain Security?

![Photo of Max Kolomaznik](https://site-assets.plasmic.app/eb79bdd689efbccb3a7e936e62b3a798.svg)

By Max Kolomaznik

|

May 15, 2022

![Kim_Lewandowski_blog_card_e6fe5d1196](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Kim_Lewandowski_blog_card_e6fe5d1196?_a=BAVMn6ID0)

In a typical manufacturing company, a supply chain is the chain of companies that you rely on to make your product. For example, a mobile phone manufacturer buys processor chips from a supplier. That supplier needs to buy a part from another manufacturer. And that manufacturer relies on yet another company for the raw metal.

But what is the software supply chain? And how do you keep it secure? We spoke with Kim Lewandowski, co-founder and head of product at [Chainguard](https://www.chainguard.dev/), to explain the details.

## Your software supply chain is more complex than you think

The software supply chain can be complicated. Mainly because it’s difficult to know how far it reaches. Take a simple example: If you use Salesforce to keep track of your customers, you store your customers’ data on Salesforce’s servers. Not a problem, surely? But Salesforce could have a breach. And what about the servers themselves? Those servers might run on Windows. If that has a security bug, hackers have another way in. How about the software that Salesforce uses to host its website? If that is hacked, you have yet another breach.

> _“When I think of the software supply chain, it’s all the code and all the mechanics and the processes that went into delivering that core piece of software at the end,” Kim explained. “It’s all the bits and pieces that go into making these things.”_ 
> 
> _\-_[On the Dev Interrupted Podcast at 11:28](https://open.spotify.com/episode/7ou8TToGQFK0rT0I9Ie0TF?si=f251e8cb75fc46ca)

## Keeping the software supply chain secure involves checking who has keys

The important part of keeping your supply chain secure is making sure that you track down what you’re using. And checking that they’re secure and reliable. Every new third party can be a potential problem. If you don’t do your due diligence, you won’t know what risks you’re taking.

As Kim explained, a favorite analogy of hers is thinking about doing construction work on your own home.

> _“You have a contractor. Well, they need keys. They have subcontractors. You give the keys out to all their subcontractors. Who are they? Where are they from? What materials are they bringing into your house?”_ 
> 
> \-[On the Dev Interrupted Podcast at 12:09](https://open.spotify.com/episode/7ou8TToGQFK0rT0I9Ie0TF?si=f251e8cb75fc46ca)

## The more third party tools you use, the more out of control it can become

It all comes down to accountability. It can easily start spreading rapidly. One third-party tool that you use to create your software might rely on five separate third parties. And you don’t know what code they’ve got hidden under the hood. Your keys are suddenly all over the place.

The only way to keep it under control is to remind yourself to check and to do regular audits of the services you use. Kim believes it’s helpful to think of every new tool as a package coming to your home.

> _“How is your package getting to your house?” Kim said. “What truck is it riding on and who is driving those trucks?”_ 
> 
> \-[On the Dev Interrupted Podcast at 12:44](https://open.spotify.com/episode/7ou8TToGQFK0rT0I9Ie0TF?si=f251e8cb75fc46ca)

## Get the full conversation

If you’d like to learn more about the software supply chain, and how to make sure that yours is secure, you can [**listen to the full conversation with Kim over on our podcast**.](https://open.spotify.com/episode/7ou8TToGQFK0rT0I9Ie0TF?si=f251e8cb75fc46ca)

**_Starved for top-level software engineering content? Need some good tips on how to manage your team? This article is inspired by [Dev Interrupted](https://devinterrupted.com/podcasts/) \- the go-to podcast for engineering leaders._**

_Dev Interrupted features expert guests from around the world to explore strategy and day-to-day topics ranging from dev team metrics to accelerating delivery. With new guests every week from Google to small startups, the Dev Interrupted Podcast is a fresh look at the world of software engineering and engineering management._

**[_Listen and subscribe on your streaming service of choice today._](https://devinterrupted.com/podcasts/)**

[![Discover Our Most Popular Podcasts](https://assets.linearb.io/uploads/favorite-podcasts-recap-3-1-1024x576.png)](https://devinterrupted.com/podcasts/)

Join the Dev Interrupted discord

## Real conversations with top engineering leaders

Find us on

[](https://www.linkedin.com/showcase/dev-interrupted/)
[](https://devinterrupted.substack.com/)

## Your next read

[![Cover image for Why Engineering Efficiency Should Win the Dev Productivity Debate](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Untitled_design_28_8426f08c75?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/blog/why-engineering-efficiency-should-win-the-dev-productivity-debate-1)

Dev Interrupted

[Why Engineering Efficiency Should Win the Dev Productivity Debate](https://linearb.io/dev-interrupted/blog/why-engineering-efficiency-should-win-the-dev-productivity-debate-1)

It's time to settle the McKinsey productivity debate.

[![Cover image for How Healthy Engineering Teams Invest Their Time](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/Untitled_design_23_f5da1f701d?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/blog/how-healthy-engineering-teams-invest-their-time)

Dev Interrupted

[How Healthy Engineering Teams Invest Their Time](https://linearb.io/dev-interrupted/blog/how-healthy-engineering-teams-invest-their-time)

In a perfect world, leaders could show a direct line between engineering efforts and business impact. In reality, the nature of software engineering is...

[![Cover image for 6 Proven Strategies For Being A Great Platform Engineer](https://assets.linearb.io/image/upload/c_limit,w_2560/f_auto/q_auto/v1/ed18598c_47e3_4396_85a6_e7aa6a65e827_1428x842_152822c90f?_a=BAVMn6ID0)](https://linearb.io/dev-interrupted/blog/6-proven-strategies-for-being-a-great-platform-engineer)

Dev Interrupted

[6 Proven Strategies For Being A Great Platform Engineer](https://linearb.io/dev-interrupted/blog/6-proven-strategies-for-being-a-great-platform-engineer)

Despite being a relatively new profession, platform engineers already have some tried and true wisdom to rely on.

## Structured data

_Machine-readable metadata (JSON-LD) embedded in the page for search/AI context — not content rendered on the page itself._

```json
{
  "@context": "https://schema.org",
  "@type": "Organization",
  "name": "LinearB",
  "url": "https://linearb.io/",
  "logo": "https://assets.linearb.io/image/upload/v1715628027/logo-mark-lg.svg",
  "description": "LinearB is the engineering productivity platform that helps engineering leaders prove AI is improving throughput without sacrificing delivery confidence, flow efficiency, or developer experience.",
  "sameAs": [
    "https://www.linkedin.com/company/linearb"
  ],
  "award": [
    {
      "@type": "Award",
      "name": "LinearB is a Leader in the 2026 Gartner® Magic Quadrant™ for Developer Productivity Insight Platforms",
      "dateAwarded": "2026",
      "awardedBy": {
        "@type": "Organization",
        "name": "Gartner®"
      }
    },
    {
      "@type": "Award",
      "name": "Great Place to Work Certification",
      "dateAwarded": "2025-2027",
      "awardedBy": {
        "@type": "Organization",
        "name": "Great Place to Work"
      }
    },
    {
      "@type": "Award",
      "name": "America's Best Startup Employers 2025",
      "dateAwarded": "2025",
      "awardedBy": {
        "@type": "Organization",
        "name": "Forbes Magazine"
      }
    }
  ],
  "hasCertification": [
    {
      "@type": "Certification",
      "name": "SOC 1 Type 2"
    },
    {
      "@type": "Certification",
      "name": "SOC 2 Type 2"
    },
    {
      "@type": "Certification",
      "name": "GDPR Compliance certification"
    },
    {
      "@type": "Certification",
      "name": "ISO 27001"
    }
  ]
}
```

## More on linearb.io

### Top navigation

- [Book a Demo](https://linearb.io/book-a-demo)
- [AI Code Reviews — Catch security risks, bugs, and spec mismatches](https://linearb.io/platform/ai-code-reviews)
- [AI & Productivity Insights — See how AI tools affect cycle time and delivery speed](https://linearb.io/platform/ai-developer-productivity-insights)
- [Measure AI Impact — Track AI adoption and tie it to delivery outcomes](https://linearb.io/use-case/measure-ai-impact)
- [MCP Server — Chat with your data to spot patterns and boost output](https://linearb.io/platform/mcp-server)
- [Resource Allocation — Cost initiatives and shape your investment strategy](https://linearb.io/platform/resource-allocation)
- [Cost Capitalization — Capitalize engineering costs with audit-ready reports](https://linearb.io/platform/cost-capitalization)
- [Dev Team Management — Set targets and tie throughput to business outcomes](https://linearb.io/platform/goals-and-reporting)
- [DevOps Workflow Automation — Policy-based PR routing, approvals, and tests](https://linearb.io/platform/ai-workflow-governance)
- [AI Powered Support — Unify AI and human code delivery in one clear view](https://linearb.io/use-case/ai-powered-support)
- [Optimization — Surface friction with feedback and MCP insights](https://linearb.io/platform/developer-experience)
- [Reporting — Spot what's working and what needs attention](https://linearb.io/use-case/measuring-developer-experience)
- [Surveys — Turn developer feedback into actionable signals](https://linearb.io/platform/developer-surveys)
- [Platform overview](https://linearb.io/platform/overview)
- [Register now](https://linearb.io/event/engineering-productivity-gap)
- [Customers](https://linearb.io/customers)
- [Pricing](https://linearb.io/pricing)
- [Why choose LinearB — Explore your data. Measure performance. Act to improve it.](https://linearb.io/why-linearb)
- [APEX framework — The operating model for AI-era engineering teams](https://linearb.io/resources/apex-framework)
- [Anti-FAQ — The questions other vendors won't answer](https://linearb.io/why-linearb/anti-faq)
- [Security — Enterprise-grade compliance and zero code access](https://linearb.io/security)
- [Build vs. buy — The hidden cost of building it yourself](https://linearb.io/resources/build-vs-buy)
- [Dev Interrupted Podcast — Conversations with engineering leaders](https://linearb.io/dev-interrupted/podcasts)
- [Reports & Guides — Deep dives on productivity and delivery](https://linearb.io/resources)
- [Webinars — Expert sessions on productivity and AI](https://linearb.io/resources?category=workshops)
- [Metrics Benchmarks — See how your engineering org stacks up](https://linearb.io/resources/software-engineering-benchmarks-report)
- [Blog — Product updates and practical insights](https://linearb.io/blog)
- [Help Center — Documentation, setup, and support](https://linearb.helpdocs.io)
- [API Docs](https://docs.linearb.io/api-overview)
- [Status](https://www.linearbstatus.com/)
- [Integrations](https://linearb.io/integrations)
- [LinearB Library](https://linearb.io/library)
- [Engineering metrics](https://linearb.io/library/engineering-metrics)
- [Platform engineering](https://linearb.io/library/platform-engineering)
- [Engineering glossary](https://linearb.io/library/engineering-glossary)
- [Developer productivity](https://linearb.io/library/developer-productivity)
- [AI in software development](https://linearb.io/library/ai-in-software-development)
- [Engineering management](https://linearb.io/library/engineering-management)
- [Developer experience](https://linearb.io/library/developer-experience)
- [DevOps](https://linearb.io/library/devops)
- [Engineering operations and the context layer](https://linearb.io/library/engineering-operations)
- [Engineering efficiency](https://linearb.io/library/engineering-efficiency)
- [Software delivery](https://linearb.io/library/software-delivery)
- [Research and data](https://linearb.io/library/engineering-benchmarks-and-research)
- [LinearB is a Leader in the 2026 Gartner® Magic Quadrant™ for Developer Productivity Insight Platforms](https://linearb.io/resources/gartner-magic-quadrant-dpi-platforms-2026)
- [Sign in](https://app.linearb.io/login)
- [Enterprise](https://linearb.io/solutions/enterprise)
- [Contact](https://linearb.io/contact-us)
- [About us](https://linearb.io/about-us)
- [Careers](https://linearb.io/careers)
- [Service agreement](https://linearb.io/services-agreement)
- [Privacy policy](https://linearb.io/privacy-policy)
- [DPA](https://linearb.io/data-processing-agreement)
- [Security FAQ](https://linearb.io/security-faq)
- [Substack](https://devinterrupted.substack.com/)

### Footer

_Additional links from the site footer, not repeated from the top navigation above._

- [GitHub](https://github.com/linear-b)
- [LinkedIn](https://www.linkedin.com/company/linearb)
- [Twitter](https://twitter.com/LinearB_Inc)