vulns.co
/
GKData.io MCP

SCSecurity theme

Software supply-chain security.

Build systems, package provenance, release integrity, and automation trust. 6 disclosures · 4 related references · 2 diagrams.

Connected collection

Disclosures

Connected collection

Related learning

National Institute of Standards and Technology Architecture Guide

NIST SP 800-190: Application Container Security Guide

A foundational model of container images, registries, orchestration, runtimes and host security. It explains shared-kernel risk, workload separation, constrained runtime permissions and lifecycle maintenance.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

Authorization Cheat Sheet

Practical design guidance covering least privilege, deny-by-default behavior, consistent per-request decisions, failure handling, logging, and authorization regression tests.

Reviewed 2026-10-02Read

OWASP Cheat Sheet Series Implementation Guide

OWASP Transaction Authorization

Explains operation-specific approval: show significant transaction details, preserve authorized data, enforce valid state transitions and recheck authorization at execution.

Reviewed 2026-10-02Read

SLSA Community Security Standard

SLSA v1.2: supply-chain security and build provenance

Learn to assess software supply-chain assurance using distinct source and build tracks. The build track progresses from recording provenance to authenticated hosted builds and stronger platform isolation. Build…

Reviewed 2026-10-02Read

Connected collection

Visual models

Related learning follows the topic crosswalk or an explicit diagram relationship. It does not classify a resource as a finding. Topics overlap, so their counts should not be added together.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software