Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “Software supply chain”
3 publicationsTechnical guideSource-based analysisTechnical guideSource-based analysisTechnical guideSource-based analysis
Security evidence for AI release decisions
A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.
AI systems · By Cloud Security DeskTurn SBOM and VEX records into patch decisions
A VEX statement is an assertion about a specific product and vulnerability. Match its scope and conditions before using it to suppress a finding.
Workload security · CISA / OpenVEX / CycloneDX / OASIS · By Cloud Security DeskTreat model downloads as software supply chain changes
Review weights, custom code, dependencies, and runtime authority as separate decisions before promoting a downloaded model into a trusted environment.
AI systems · Hugging Face · By Cloud Security Desk