Câu hỏi audit khó nhất hiện nay không phải "code có CVE không?" mà là "làm sao chứng minh artifact đang chạy production được build từ chính source này, không bị inject?".
Ba loại supply chain attack phổ biến
- Dependency confusion / typosquat (npm, pypi, RubyGems): publish package có tên gần giống thư viện nội bộ.
- Source compromise (xz utils, Codecov bash uploader): inject malicious code vào dự án thượng nguồn.
- Build poisoning (SolarWinds): compromise build server, inject vào artifact mà source code vẫn sạch.
Khung tiêu chuẩn ứng phó là SLSA (Supply-chain Levels for Software Artifacts) do OpenSSF maintain.
SLSA — bốn cấp độ build integrity
| Level | Yêu cầu chính |
|---|---|
| L1 | Build có document, sinh provenance cơ bản. |
| L2 | Build chạy trên hosted CI, provenance được sign, source theo version control. |
| L3 | Build trong môi trường isolated/hardened, provenance không thể bị giả mạo bởi user. |
| L4 | Hermetic, reproducible build, two-party review. |
Mục tiêu thực tế cho phần lớn tổ chức: SLSA Build L2-L3. L4 còn hiếm và tốn kém.
SBOM: CycloneDX hay SPDX?
Hai format chuẩn:
- CycloneDX (OWASP): tập trung security use case, hỗ trợ vulnerability, services, ML model. Tool ecosystem phong phú (Trivy, Syft, Dependency-Track).
- SPDX (Linux Foundation): tập trung license compliance, được nhiều regulator chấp nhận (US EO 14028).
Chọn 1 chính, có thể export sang format kia khi cần. Mỗi artifact production phải có SBOM được sinh tự động trong CI và lưu cùng artifact.
Sigstore: keyless signing cho mọi artifact
Sigstore gồm 3 component:
- Cosign: CLI sign/verify image, blob, attestation.
- Fulcio: CA cấp short-lived cert dựa OIDC identity (5 phút TTL).
- Rekor: transparency log bất biến lưu mọi signature — kiểm tra xem có signature nào bất thường được tạo bằng identity của bạn không.
Lợi ích lớn nhất: không có private key cần lưu, rotate hay backup.
Provenance & in-toto attestation
Provenance là metadata mô tả: ai build, từ source nào, bằng tool gì, vào lúc nào. Format chuẩn là in-toto attestation với predicate type https://slsa.dev/provenance/v1.
Workflow GitHub Actions có generator chính thức:
jobs: build: outputs: digest: ${{ steps.push.outputs.digest }} # ... build & push image
provenance: needs: [build] permissions: id-token: write packages: write contents: read uses: slsa-framework/slsa-github-generator/.github/workflows/[email protected] with: image: ghcr.io/org/app digest: ${{ needs.build.outputs.digest }} registry-username: ${{ github.actor }}
Workflow này build trong reusable workflow isolated, sinh provenance + ký bằng Cosign keyless — đạt SLSA L3 không cần code thêm.
Verify provenance trước deploy
Bằng cosign verify-attestation:
cosign verify-attestation --type slsaprovenance \
--certificate-identity-regexp "https://github.com/org/.+/.github/workflows/build.yml@.+" \
--certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
ghcr.io/org/app@sha256:...
Hoặc enforce trong cluster qua Kyverno verifyImages với attestor là OIDC subject. Pod sẽ bị admission từ chối nếu image không có provenance đúng.
Quản lý dependency thông minh
- Pin theo digest/lockfile:
package-lock.json,poetry.lock,go.sum. Không bao giờlatest. - Pin GitHub Action theo SHA chứ không phải tag — tag có thể bị move.
- Vendor mirror cho package nội bộ (Artifactory, Nexus) thay vì pull thẳng từ npm/pypi public.
- Renovate/Dependabot có policy: auto-merge patch, manual review minor/major, có cooldown để tránh chính bản malicious vừa publish.
Checklist supply chain ngắn
- Mọi artifact production có SBOM CycloneDX/SPDX và được lưu trữ.
- Image được sign Cosign keyless, signature lưu Rekor.
- Build chạy trong reusable workflow isolated (đạt SLSA L2-L3).
- Cluster có policy verify signature + provenance trước khi admit pod.
- Dependency pin theo lockfile + digest, mirror nội bộ.
- Dependency-Track theo dõi long-tail CVE qua SBOM.
Kết luận
Supply chain security không còn là tuỳ chọn — EU CRA, US EO 14028 và nhiều khách hàng enterprise đã yêu cầu SBOM và signed artifact trong RFP. Tin tốt: stack mở Sigstore + SLSA + CycloneDX cho phép đạt SLSA L3 với chi phí gần như bằng 0 nhờ reusable workflow của OpenSSF. Hãy coi đây là baseline kỹ thuật cần có trong 2026.



