Software Supply Chain Security Gains Momentum as SBOM Programs Mature
Organizations are increasingly recognizing that software‑supply‑chain risk has moved beyond a niche concern. Regulators, customers and security teams all demand transparent software inventories, prompting many firms to adopt SBOM (Software Bill of Materials) management programmes. Mature programmes integrate continuous component mapping, automated vulnerability tracking and clear ownership, enabling rapid response when critical flaws are disclosed.
A recent JFrog "Software Supply Chain Security State of the Union" report highlights a sharp rise in malicious packages—over 177,000 new harmful artifacts were identified, including a 451 % increase in compromised npm packages. The report also flags AI‑generated code and model repositories as emerging attack surfaces, with hundreds of tampered AI models discovered on platforms such as Hugging Face. Despite these threats, only about 40 % of surveyed firms have automated detection of malicious packages, and governance practices often remain paper‑only, leaving many organizations under‑prepared for the evolving risk landscape.