SAP / risk-explorer-for-software-supply-chains

A taxonomy of attacks on software supply chains in the form of an attack tree, based on and linked to numerous real-world incidents and other resources. The taxonomy as well as related safeguards can be explored using an interactive visualization tool.
https://sap.github.io/risk-explorer-for-software-supply-chains/
Apache License 2.0
71 stars 14 forks source link

Add new references about attacks on CocoaPods and one about using fake PyPI mirror #115

Closed piergiorgioladisa closed 5 months ago

piergiorgioladisa commented 5 months ago

@henrikplate @serenaponta it would be nice if you could review the PR and agree on the assignment to the right attack vectors