Supply Chain Security
Explore planned Supply Chain Security capabilities and enhancements.
This page tracks planned capabilities and enhancements for Supply Chain Security.
Now
Q3 2026, August 2026 - October 2026
Exemption Management Manage exemptions for OSS dependencies across artifacts and repositories with auditability and lifecycle tracking.
OSS Risk Scoring Introduce contextual risk scoring for open-source dependencies based on end-of-life, malicious package, and vulnerability risks.
SCS plugins for Jenkins Enable SCS capabilities in Jenkins pipelines with native plugins for SBOM generation, SLSA provenance, artifact signing, verification, and policy enforcement.
Cosign AWS KMS support Leverage keys from AWS KMS to sign and verify artifacts.
Google Cloud KMS support Leverage keys from Google Cloud KMS to sign and verify artifacts.
AIBOM Risk Assess risk across AI models, datasets, agents, and related components in AIBOMs.
SCS Auto PR (GitLab, Bitbucket) Automatically generate pull requests in GitLab and Bitbucket to update outdated OSS dependencies.
License Attribution Comprehensive license attribution reporting for open-source dependencies across artifacts and repositories.
SCA Remediation Agent Deliver intelligent insights and automate remediations for SCA findings.
Next
Q4 2026, November 2026 - January 2027
Global Artifact & Repository visibility Account-wide views of repositories and artifacts for unified oversight across resources.
OpenSSF Integration Enforce OpenSSF rules to strengthen build integrity, dependency hygiene, and supply chain security.
Repo Security Posture Management for Harness Code Identify repository misconfigurations based on CIS v1.0 and OWASP Top 10 CI/CD Risks.
VEX support Generate and consume VEX documents to record vulnerability exploitability in artifacts.
Later
Q1 2027+, February 2027 & beyond
OSS Top 10 Policies Out-of-the-box policies identify OSS risks and can block builds and deployments.
NIST SP800-204D Support Out-of-the-box rules support NIST SP800-204D compliance standards.
SLSA Policies Out-of-the-box policies ensure SLSA Level 1, Level 2, and Level 3 compliance.
CICD Static Rules Enhance the rule list to detect CI/CD misconfigurations.
Run Time Security for CI/CD Pipelines Detect anomalies and unauthorized activity through real-time system and network event monitoring.
Released
What has been released
SCS Usage Analytics Centralized analytics dashboard for SCS usage, adoption, and engagement across SCS steps.
AIBOM Gain visibility into AI models, datasets, and prompts used across your systems.
SCS Plugins for GitLab Enable SCS capabilities for GitLab repositories with native plugins for SBOM generation, SAST, SCA, and secrets scanning.
Zero day Agent Use an AI-driven agent to identify impacted artifacts and repositories after a zero-day vulnerability disclosure.
Package Age policy Enforce a cooldown period for newly published open-source packages.
Automate OSS Dependency Updates with Harness AI Use Harness AI to generate pull requests for outdated dependencies.
Support for Bitbucket Onboard Bitbucket repositories for SBOM generation, SAST, SCA, and secrets scans.
Keyless signing support using OIDC Support SBOM and SLSA attestations and artifact signing through Harness OIDC.
OSS Risks (Malicious Package Detection, TypoSquatting) Detect malicious packages, typosquatted dependencies, and suspicious components.
SLSA for non-containers Enable SLSA provenance generation and verification for non-container artifacts.
OWASP OSS Top 10 Risks View outdated, unmaintained, and end-of-life components using SBOMs.
Repo Security Posture Management for GitHub Identify repository misconfigurations based on CIS v1.0 and OWASP Top 10 CI/CD Security Risks.
Artifact Chain of Custody Review an artifact chain of custody across every artifact built and deployed in a CI/CD pipeline.
Compliance Report Generation Generate and download reports for standards including CIS v1.0 and OWASP Top 10 CI/CD Security Risks.
SBOM & SLSA support with GitHub Actions Generate SBOMs and achieve SLSA compliance for artifacts built in GitHub Actions.
Artifact Signing and Verification (Containers & Non-Containers) Ensure built artifacts are not tampered with before deployment.
AI Chatbot AI-powered chatbot capabilities within the SCS module.
SBOM Direct and Indirect Dependencies Analyze direct and transitive OSS dependencies for comprehensive risk insights.
Last updated
Was this helpful?