> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/roadmap/supply-chain-security.md).

# Supply Chain Security

Explore planned Supply Chain Security capabilities and enhancements.

This page tracks planned capabilities and enhancements for Supply Chain Security.

### Now

Q3 2026, August 2026 - October 2026

<table data-column-title-hidden data-view="cards" data-search="true"><thead><tr><th>Tag<select multiple><option value="risk-compliance" label="Risk &#x26; Compliance" color="blue"></option><option value="appsec" label="AppSec" color="blue"></option><option value="integration" label="Integration" color="blue"></option><option value="repo-security" label="Repo Security" color="blue"></option><option value="artifact-security" label="Artifact Security" color="blue"></option><option value="aibom" label="AIBOM" color="blue"></option><option value="ai" label="AI" color="blue"></option></select></th><th>Feature</th></tr></thead><tbody><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance, </span><span data-option="appsec">AppSec</span></td><td><strong>Exemption Management</strong><br>Manage exemptions for OSS dependencies across artifacts and repositories with auditability and lifecycle tracking.</td></tr><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance</span></td><td><strong>OSS Risk Scoring</strong><br>Introduce contextual risk scoring for open-source dependencies based on end-of-life, malicious package, and vulnerability risks.</td></tr><tr><td><span data-option="integration">Integration, </span><span data-option="repo-security">Repo Security</span></td><td><strong>SCS plugins for Jenkins</strong><br>Enable SCS capabilities in Jenkins pipelines with native plugins for SBOM generation, SLSA provenance, artifact signing, verification, and policy enforcement.</td></tr><tr><td><span data-option="integration">Integration, </span><span data-option="artifact-security">Artifact Security</span></td><td><strong>Cosign AWS KMS support</strong><br>Leverage keys from AWS KMS to sign and verify artifacts.</td></tr><tr><td><span data-option="integration">Integration, </span><span data-option="artifact-security">Artifact Security</span></td><td><strong>Google Cloud KMS support</strong><br>Leverage keys from Google Cloud KMS to sign and verify artifacts.</td></tr><tr><td><span data-option="aibom">AIBOM, </span><span data-option="risk-compliance">Risk &#x26; Compliance</span></td><td><strong>AIBOM Risk</strong><br>Assess risk across AI models, datasets, agents, and related components in AIBOMs.</td></tr><tr><td><span data-option="integration">Integration</span></td><td><strong>SCS Auto PR (GitLab, Bitbucket)</strong><br>Automatically generate pull requests in GitLab and Bitbucket to update outdated OSS dependencies.</td></tr><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance</span></td><td><strong>License Attribution</strong><br>Comprehensive license attribution reporting for open-source dependencies across artifacts and repositories.</td></tr><tr><td><span data-option="ai">AI, </span><span data-option="appsec">AppSec</span></td><td><strong>SCA Remediation Agent</strong><br>Deliver intelligent insights and automate remediations for SCA findings.</td></tr></tbody></table>

### Next

Q4 2026, November 2026 - January 2027

<table data-column-title-hidden data-view="cards" data-search="true"><thead><tr><th>Tag<select multiple><option value="risk-compliance" label="Risk &#x26; Compliance" color="blue"></option><option value="integration" label="Integration" color="blue"></option><option value="openssf" label="OpenSSF" color="blue"></option><option value="repo-security" label="Repo Security" color="blue"></option><option value="sbom" label="SBOM" color="blue"></option></select></th><th>Feature</th></tr></thead><tbody><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance</span></td><td><strong>Global Artifact &#x26; Repository visibility</strong><br>Account-wide views of repositories and artifacts for unified oversight across resources.</td></tr><tr><td><span data-option="integration">Integration, </span><span data-option="openssf">OpenSSF</span></td><td><strong>OpenSSF Integration</strong><br>Enforce OpenSSF rules to strengthen build integrity, dependency hygiene, and supply chain security.</td></tr><tr><td><span data-option="repo-security">Repo Security</span></td><td><strong>Repo Security Posture Management for Harness Code</strong><br>Identify repository misconfigurations based on CIS v1.0 and OWASP Top 10 CI/CD Risks.</td></tr><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance, </span><span data-option="sbom">SBOM</span></td><td><strong>VEX support</strong><br>Generate and consume VEX documents to record vulnerability exploitability in artifacts.</td></tr></tbody></table>

### Later

Q1 2027+, February 2027 & beyond

<table data-column-title-hidden data-view="cards" data-search="true"><thead><tr><th>Tag<select multiple><option value="governance" label="Governance" color="blue"></option><option value="risk-compliance" label="Risk &#x26; Compliance" color="blue"></option><option value="slsa" label="SLSA" color="blue"></option><option value="artifact-security" label="Artifact Security" color="blue"></option><option value="cicd-security" label="CI/CD Security" color="blue"></option><option value="run-time-security" label="Run time Security" color="blue"></option></select></th><th>Feature</th></tr></thead><tbody><tr><td><span data-option="governance">Governance, </span><span data-option="risk-compliance">Risk &#x26; Compliance</span></td><td><strong>OSS Top 10 Policies</strong><br>Out-of-the-box policies identify OSS risks and can block builds and deployments.</td></tr><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance</span></td><td><strong>NIST SP800-204D Support</strong><br>Out-of-the-box rules support NIST SP800-204D compliance standards.</td></tr><tr><td><span data-option="slsa">SLSA, </span><span data-option="artifact-security">Artifact Security</span></td><td><strong>SLSA Policies</strong><br>Out-of-the-box policies ensure SLSA Level 1, Level 2, and Level 3 compliance.</td></tr><tr><td><span data-option="cicd-security">CI/CD Security</span></td><td><strong>CICD Static Rules</strong><br>Enhance the rule list to detect CI/CD misconfigurations.</td></tr><tr><td><span data-option="run-time-security">Run time Security</span></td><td><strong>Run Time Security for CI/CD Pipelines</strong><br>Detect anomalies and unauthorized activity through real-time system and network event monitoring.</td></tr></tbody></table>

### Released

What has been released

<table data-column-title-hidden data-view="cards" data-search="true"><thead><tr><th>Tag<select multiple><option value="analytics" label="Analytics" color="blue"></option><option value="aibom" label="AIBOM" color="blue"></option><option value="integration" label="Integration" color="blue"></option><option value="repo-security" label="Repo Security" color="blue"></option><option value="ai" label="AI" color="blue"></option><option value="appsec" label="AppSec" color="blue"></option><option value="risk-compliance" label="Risk &#x26; Compliance" color="blue"></option><option value="governance" label="Governance" color="blue"></option><option value="dependency-management" label="Dependency Management" color="blue"></option><option value="artifact-security" label="Artifact Security" color="blue"></option><option value="slsa" label="SLSA" color="blue"></option><option value="owasp" label="OWASP" color="blue"></option><option value="audit-trail" label="Audit Trail" color="blue"></option><option value="github-actions" label="GitHub Actions" color="blue"></option><option value="sbom" label="SBOM" color="blue"></option></select></th><th>Feature</th></tr></thead><tbody><tr><td><span data-option="analytics">Analytics</span></td><td><strong>SCS Usage Analytics</strong><br>Centralized analytics dashboard for SCS usage, adoption, and engagement across SCS steps.</td></tr><tr><td><span data-option="aibom">AIBOM</span></td><td><strong>AIBOM</strong><br>Gain visibility into AI models, datasets, and prompts used across your systems.</td></tr><tr><td><span data-option="integration">Integration, </span><span data-option="repo-security">Repo Security</span></td><td><strong>SCS Plugins for GitLab</strong><br>Enable SCS capabilities for GitLab repositories with native plugins for SBOM generation, SAST, SCA, and secrets scanning.</td></tr><tr><td><span data-option="ai">AI, </span><span data-option="appsec">AppSec</span></td><td><strong>Zero day Agent</strong><br>Use an AI-driven agent to identify impacted artifacts and repositories after a zero-day vulnerability disclosure.</td></tr><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance, </span><span data-option="governance">Governance</span></td><td><strong>Package Age policy</strong><br>Enforce a cooldown period for newly published open-source packages.</td></tr><tr><td><span data-option="dependency-management">Dependency Management</span></td><td><strong>Automate OSS Dependency Updates with Harness AI</strong><br>Use Harness AI to generate pull requests for outdated dependencies.</td></tr><tr><td><span data-option="integration">Integration, </span><span data-option="repo-security">Repo Security</span></td><td><strong>Support for Bitbucket</strong><br>Onboard Bitbucket repositories for SBOM generation, SAST, SCA, and secrets scans.</td></tr><tr><td><span data-option="artifact-security">Artifact Security</span></td><td><strong>Keyless signing support using OIDC</strong><br>Support SBOM and SLSA attestations and artifact signing through Harness OIDC.</td></tr><tr><td><span data-option="dependency-management">Dependency Management, </span><span data-option="repo-security">Repo Security</span></td><td><strong>OSS Risks (Malicious Package Detection, TypoSquatting)</strong><br>Detect malicious packages, typosquatted dependencies, and suspicious components.</td></tr><tr><td><span data-option="slsa">SLSA</span></td><td><strong>SLSA for non-containers</strong><br>Enable SLSA provenance generation and verification for non-container artifacts.</td></tr><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance, </span><span data-option="owasp">OWASP</span></td><td><strong>OWASP OSS Top 10 Risks</strong><br>View outdated, unmaintained, and end-of-life components using SBOMs.</td></tr><tr><td><span data-option="repo-security">Repo Security</span></td><td><strong>Repo Security Posture Management for GitHub</strong><br>Identify repository misconfigurations based on CIS v1.0 and OWASP Top 10 CI/CD Security Risks.</td></tr><tr><td><span data-option="governance">Governance, </span><span data-option="audit-trail">Audit Trail</span></td><td><strong>Artifact Chain of Custody</strong><br>Review an artifact chain of custody across every artifact built and deployed in a CI/CD pipeline.</td></tr><tr><td><span data-option="risk-compliance">Risk &#x26; Compliance</span></td><td><strong>Compliance Report Generation</strong><br>Generate and download reports for standards including CIS v1.0 and OWASP Top 10 CI/CD Security Risks.</td></tr><tr><td><span data-option="artifact-security">Artifact Security, </span><span data-option="github-actions">GitHub Actions</span></td><td><strong>SBOM &#x26; SLSA support with GitHub Actions</strong><br>Generate SBOMs and achieve SLSA compliance for artifacts built in GitHub Actions.</td></tr><tr><td><span data-option="artifact-security">Artifact Security</span></td><td><strong>Artifact Signing and Verification (Containers &#x26; Non-Containers)</strong><br>Ensure built artifacts are not tampered with before deployment.</td></tr><tr><td><span data-option="ai">AI</span></td><td><strong>AI Chatbot</strong><br>AI-powered chatbot capabilities within the SCS module.</td></tr><tr><td><span data-option="sbom">SBOM</span></td><td><strong>SBOM Direct and Indirect Dependencies</strong><br>Analyze direct and transitive OSS dependencies for comprehensive risk insights.</td></tr></tbody></table>

{% @harness-feedback/feedback module="roadmap" pagePath="roadmap/supply-chain-security" %}
