For the complete documentation index, see llms.txt. This page is also available as Markdown.

Supply Chain Security

Explore planned Supply Chain Security capabilities and enhancements.

This page tracks planned capabilities and enhancements for Supply Chain Security.

Now

Q3 2026, August 2026 - October 2026

Risk & ComplianceAppSec

Exemption Management Manage exemptions for OSS dependencies across artifacts and repositories with auditability and lifecycle tracking.

Risk & Compliance

OSS Risk Scoring Introduce contextual risk scoring for open-source dependencies based on end-of-life, malicious package, and vulnerability risks.

IntegrationRepo Security

SCS plugins for Jenkins Enable SCS capabilities in Jenkins pipelines with native plugins for SBOM generation, SLSA provenance, artifact signing, verification, and policy enforcement.

IntegrationArtifact Security

Cosign AWS KMS support Leverage keys from AWS KMS to sign and verify artifacts.

IntegrationArtifact Security

Google Cloud KMS support Leverage keys from Google Cloud KMS to sign and verify artifacts.

AIBOMRisk & Compliance

AIBOM Risk Assess risk across AI models, datasets, agents, and related components in AIBOMs.

Integration

SCS Auto PR (GitLab, Bitbucket) Automatically generate pull requests in GitLab and Bitbucket to update outdated OSS dependencies.

Risk & Compliance

License Attribution Comprehensive license attribution reporting for open-source dependencies across artifacts and repositories.

AIAppSec

SCA Remediation Agent Deliver intelligent insights and automate remediations for SCA findings.

Next

Q4 2026, November 2026 - January 2027

Risk & Compliance

Global Artifact & Repository visibility Account-wide views of repositories and artifacts for unified oversight across resources.

IntegrationOpenSSF

OpenSSF Integration Enforce OpenSSF rules to strengthen build integrity, dependency hygiene, and supply chain security.

Repo Security

Repo Security Posture Management for Harness Code Identify repository misconfigurations based on CIS v1.0 and OWASP Top 10 CI/CD Risks.

Risk & ComplianceSBOM

VEX support Generate and consume VEX documents to record vulnerability exploitability in artifacts.

Later

Q1 2027+, February 2027 & beyond

GovernanceRisk & Compliance

OSS Top 10 Policies Out-of-the-box policies identify OSS risks and can block builds and deployments.

Risk & Compliance

NIST SP800-204D Support Out-of-the-box rules support NIST SP800-204D compliance standards.

SLSAArtifact Security

SLSA Policies Out-of-the-box policies ensure SLSA Level 1, Level 2, and Level 3 compliance.

CI/CD Security

CICD Static Rules Enhance the rule list to detect CI/CD misconfigurations.

Run time Security

Run Time Security for CI/CD Pipelines Detect anomalies and unauthorized activity through real-time system and network event monitoring.

Released

What has been released

Analytics

SCS Usage Analytics Centralized analytics dashboard for SCS usage, adoption, and engagement across SCS steps.

AIBOM

AIBOM Gain visibility into AI models, datasets, and prompts used across your systems.

IntegrationRepo Security

SCS Plugins for GitLab Enable SCS capabilities for GitLab repositories with native plugins for SBOM generation, SAST, SCA, and secrets scanning.

AIAppSec

Zero day Agent Use an AI-driven agent to identify impacted artifacts and repositories after a zero-day vulnerability disclosure.

Risk & ComplianceGovernance

Package Age policy Enforce a cooldown period for newly published open-source packages.

Dependency Management

Automate OSS Dependency Updates with Harness AI Use Harness AI to generate pull requests for outdated dependencies.

IntegrationRepo Security

Support for Bitbucket Onboard Bitbucket repositories for SBOM generation, SAST, SCA, and secrets scans.

Artifact Security

Keyless signing support using OIDC Support SBOM and SLSA attestations and artifact signing through Harness OIDC.

Dependency ManagementRepo Security

OSS Risks (Malicious Package Detection, TypoSquatting) Detect malicious packages, typosquatted dependencies, and suspicious components.

SLSA

SLSA for non-containers Enable SLSA provenance generation and verification for non-container artifacts.

Risk & ComplianceOWASP

OWASP OSS Top 10 Risks View outdated, unmaintained, and end-of-life components using SBOMs.

Repo Security

Repo Security Posture Management for GitHub Identify repository misconfigurations based on CIS v1.0 and OWASP Top 10 CI/CD Security Risks.

GovernanceAudit Trail

Artifact Chain of Custody Review an artifact chain of custody across every artifact built and deployed in a CI/CD pipeline.

Risk & Compliance

Compliance Report Generation Generate and download reports for standards including CIS v1.0 and OWASP Top 10 CI/CD Security Risks.

Artifact SecurityGitHub Actions

SBOM & SLSA support with GitHub Actions Generate SBOMs and achieve SLSA compliance for artifacts built in GitHub Actions.

Artifact Security

Artifact Signing and Verification (Containers & Non-Containers) Ensure built artifacts are not tampered with before deployment.

AI

AI Chatbot AI-powered chatbot capabilities within the SCS module.

SBOM

SBOM Direct and Indirect Dependencies Analyze direct and transitive OSS dependencies for comprehensive risk insights.

Last updated

Was this helpful?