Red Hat updated its Trusted Software Supply Chain in response to an uptick of organizations integrating security protocols directly into their software processes. In other words, the vendor hopes to take advantage of the shift from reactive security measures to proactive security measures.

Industry research firm IDC predicts that by 2027, three-quarters of CIOs will tie cybersecurity tooling in with existing systems and operational processes. This proactive strategy helps IT teams identify and neutralize threats and fortify against vulnerabilities or breaches before they happen.

To that point, the updates to Red Hat Trusted Software Supply Chain improve IT teams’ ability to embed security into the application development lifecycle and establish software integrity sooner in the supply chain.

“From code time to runtime, these tools … give DevSecOps teams the ability to lay the groundwork for a more secure enterprise without impacting developer velocity or cognitive load,” Red Hat VP and GM of the Application Developer Business Unit Sarwar Raza said.

According to IDC VP Analyst of Software Development, DevOps and DevSecOps Jim Mercer, Red Hat “has continued to enhance its open source due diligence by providing safeguards against tampering and ensuring all code is stored in internal repositories and the software the company distributes is signed to improve digital provenance.”

“The Red Hat Trusted Software Supply Chain extends its existing open source security due diligence to help customers manage their open source and software supply chains using the same software supply chain that Red Hat uses to deliver trusted open source software,” Mercer said.

Signing artifacts and analyzing profiles with Red Hat

Red Hat Trusted Artifact Signer is based on the open source Sigstore project, which is now part of the Open Source Security Foundation (OpenSSF). This new capability enhances the trustworthiness of software artifacts as they move through the software supply chain by allowing developers and other stakeholders to cryptographically sign and verify each artifact with keyless certificate authority.

This identity-based signing is possible thanks to an integration with OpenID Connect, allowing organizations to be confident in the authenticity of their software supply chain without needing to manually operate a centralized key management system.

Another new capability is Red Hat Trusted Profile Analyzer, which provides development and security teams with the visibility and insight they need to assess the risk profile of an application’s codebase to proactively minimize security threats.

According to the vendor, this tool simplifies vulnerability management with a single source of truth for security documentation, including software bill of materials (SBOMs) and vulnerability exploitability exchanges (VEXs). IT teams can then analyze and monitor their organization’s software assets and other documentation for custom, third-party or open source software without further complicating operations.

Building trust in the application pipeline

Red Hat Trusted Application Pipeline combines the Trusted Profile Analyzer with the Trusted Artifact Signer and the vendor’s internal developer platform, Red Hat Developer Hub. This capability supplies security-focused software supply chain tools by pre-integrating them with self-service templates targeted at developers.

With a hub of validated software templates and guardrails that accelerate the onboarding of security-focused software, this tool helps IT teams enhance both trust and transparency.

Specifically, Red Hat’s Trusted Application Pipeline verifies pipeline compliance and supports both traceability and auditability in the continuous integration/continuous delivery (CI/CD) process by automatically validating artifact signatures and providing attestations. By scanning for vulnerabilities and checking policy compliance from within the CI/CD pipeline, IT teams can prevent suspicious build activity from being pushed into production.

Red Hat Trusted Artifact Signer and Red Hat Trusted Application Pipeline are both generally available as self-managed, on-premises capabilities, but can also be layered on top of application development platforms like Red Hat OpenShift. Red Hat Trusted Profile Analyzer is available in tech preview and will be generally available later this quarter.