Software Supply Chain Security in Cloud-Native Systems: A Zero Trust Framework for Securing APIs, Containers, Dependencies, and CI/CD Pipelines

Authors

  • Santosh Kumar Jadala Cyber Security & Business Analysis Specialist Independent Researcher USA Author

DOI:

https://doi.org/10.21590/

Keywords:

Software Supply Chain Security, Zero Trust, Cloud-Native Security, API Security, Container Security, CI/CD Security, Dependency Security, Software Provenance, DevSecOps, Software Bill of Materials.

Abstract

Software supply chain attacks have become a serious security concern in cloud-native environments, where applications depend on interconnected APIs, container images, open-source libraries, build systems, registries, and automated CI/CD pipelines. A weakness in any of these components can provide attackers with a path to alter source code, introduce malicious dependencies, steal credentials, compromise build processes, or deploy unauthorized software into production. Traditional perimeter-based security models are poorly suited to these distributed and highly automated environments because they often depend on implicit trust between internal systems and development stages. This article proposes a Zero Trust software supply chain security framework that applies continuous verification, least-privilege access, strong identity controls, software provenance, artifact integrity validation, and policy-based enforcement across the cloud-native software lifecycle. The framework addresses four major security domains: APIs, containers and cloud-native workloads, third-party dependencies, and CI/CD pipelines. It also incorporates software bills of materials, cryptographic signing, workload identity, secure build practices, runtime monitoring, and automated trust evaluation. A threat-control mapping and risk assessment model are used to examine how the proposed controls can reduce exposure to dependency poisoning, repository compromise, artifact tampering, credential theft, container attacks, and unauthorized deployment. The study provides a structured approach for integrating previously fragmented security controls into a unified supply chain security model and establishes a basis for future empirical evaluation in cloud-native production environments.

References

[1] Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero

trust architecture (NIST Special Publication 800-207). National

Institute of Standards and Technology. https://doi.org/10.6028/

NIST.SP.800-207.

[2] Chandramouli, R., & Butcher, Z. (2023). A zero trust architecture

model for access control in cloud-native applications in multilocation

environments (NIST Special Publication 800-207A).

National Institute of Standards and Technology. https://doi.

org/10.6028/NIST.SP.800-207A.

[3] Syed, N. F., Shah, S. W., Shaghaghi, A., Anwar, A., Baig, Z., &

Doss, R. (2022). Zero trust architecture (ZTA): A comprehensive

survey. IEEE Access, 10, 57143–57179. https://doi.org/10.1109/

ACCESS.2022.3174679.

[4] Chandramouli, R., & Butcher, Z. (2020). Building secure

microservices-based applications using service-mesh architecture

(NIST Special Publication 800-204A). National Institute of

Standards and Technology.

[5] Potla, R. (2023). Designing a BTP-centric integration mesh for

shop-floor IoT, MES and ERP in discrete manufacturing. Journal

of Artificial Intelligence, Machine Learning and Data Science,

1(2), 1-8.

[6] Chandramouli, R., Butcher, Z., & Chetal, A. (2021). Attribute-based

access control for microservices-based applications using a service

mesh (NIST Special Publication 800-204B). National Institute

of Standards and Technology. https://doi.org/10.6028/NIST.

SP.800-204B.

[7] Chandramouli, R., Kautz, F., & Torres-Arias, S. (2024). Strategies

for the integration of software supply chain security in DevSecOps

CI/CD pipelines (NIST Special Publication 800-204D). National

Institute of Standards and Technology.

[8] Souppaya, M., Scarfone, K., & Dodson, D. (2022). Secure software

development framework (SSDF) version 1.1: Recommendations

for mitigating the risk of software vulnerabilities (NIST Special

Publication 800-218). National Institute of Standards and

Technology. https://doi.org/10.6028/NIST.SP.800-218.

[9] Ladisa, P., Plate, H., Martinez, M., & Barais, O. (2023). SoK:

Taxonomy of attacks on open-source software supply chains. In

2023 IEEE Symposium on Security and Privacy (SP) (pp. 1509–1526).

IEEE. https://doi.org/10.1109/SP46215.2023.10179304.

[10] Okafor, C., Schorlemmer, T. R., Torres-Arias, S., & Davis, J. C.

(2022). SoK: Analysis of software supply chain security by

establishing secure design properties. In Proceedings of the

2022 Workshop on Software Supply Chain Offensive Research

and Ecosystem Defenses (pp. 15–24). Association for Computing

Machinery. https://doi.org/10.1145/3560835.3564556.

[11] Torres-Arias, S., Afzali, H., Kuppusamy, T. K., Curtmola, R., &

Cappos, J. (2019). in-toto: Providing farm-to-table guarantees

for bits and bytes. In 28th USENIX Security Symposium (USENIX

Security 19) (pp. 1393–1410). USENIX Association.

[12] Ohm, M., Plate, H., Sykosch, A., & Meier, M. (2020). Backstabber’s

knife collection: A review of open source software supply chain

attacks. In Detection of Intrusions and Malware, and Vulnerability

Assessment (pp. 23–43). Springer. https://doi.org/10.1007/978-

3-030-52683-2_2.

[13] Duan, R., Alrawi, O., Kasturi, R. P., Elder, R., Saltaformaggio, B.,

& Lee, W. (2021). Towards measuring supply chain attacks on

package managers for interpreted languages. In Proceedings

of the Network and Distributed System Security Symposium

(NDSS 2021). Internet Society. https://doi.org/10.14722/

ndss.2021.23055.

[14] Vu, D. L., Pashchenko, I., Massacci, F., Plate, H., & Sabetta, A.

(2020). Towards using source code repositories to identify

software supply chain attacks. In Proceedings of the 2020 ACM

SIGSAC Conference on Computer and Communications Security

(pp. 2093–2095). Association for Computing Machinery. https://

doi.org/10.1145/3372297.3420015.

[15] Cappos, J., Samuel, J., Baker, S. M., & Hartman, J. H. (2008). A

look in the mirror: Attacks on package managers. In Proceedings

of the 15th ACM Conference on Computer and Communications

Security (pp. 565–574). Association for Computing Machinery.

https://doi.org/10.1145/1455770.1455841.

[16] Potla, R. B. (2024). Optimizing extended warehouse management

for make-to-order plants: Slotting, wave picking, and yard

orchestration at scale. Journal of Computer Science and

Technology Studies, 6(3), 181-192.

[17] Samuel, J., Mathewson, N., Cappos, J., & Dingledine, R. (2010).

Survivable key compromise in software update systems.

In Proceedings of the 17th ACM Conference on Computer and

Communications Security (pp. 61–72). Association for Computing

Machinery. https://doi.org/10.1145/1866307.1866315.

[18] Kuppusamy, T. K., Torres-Arias, S., Diaz, V., & Cappos, J. (2016).

Diplomat: Using delegations to protect community repositories.

In 13th USENIX Symposium on Networked Systems Design and

Implementation (NSDI 16) (pp. 567–581). USENIX Association.

[19] Kuppusamy, T. K., Diaz, V., & Cappos, J. (2017). Mercury:

Bandwidth-effective prevention of rollback attacks against

community repositories. In 2017 USENIX Annual Technical

Conference (USENIX ATC 17) (pp. 673–688). USENIX Association.

[20] Kunaparaju, C. (2024). Detecting and Preventing State-

Sponsored Cyber Attacks Using Deep Learning and Behavioral

Analytics. Journal of Electrical Systems, 20, 5471-5486.

[21] Zimmermann, M., Staicu, C. A., Tenny, C., & Pradel, M. (2019).

Small world with high risks: A study of security threats in the

npm ecosystem. In 28th USENIX Security Symposium (USENIX

Security 19) (pp. 995–1010). USENIX Association.

[22] Kula, R. G., German, D. M., Ouni, A., Ishio, T., & Inoue, K. (2018).

Do developers update their library dependencies? An empirical

study on the impact of security advisories on library migration.

Empirical Software Engineering, 23(1), 384–417. https://doi.

org/10.1007/s10664-017-9521-5.

[23] Decan, A., Mens, T., & Constantinou, E. (2018). On the

impact of security vulnerabilities in the npm package

dependency network. In Proceedings of the 15th International

Conference on Mining Software Repositories (pp. 181–

191). Association for Computing Machinery. https://doi.

org/10.1145/3196398.3196401.

[24] Pashchenko, I., Plate, H., Ponta, S. E., Sabetta, A., & Massacci, F.(2018). Vulnerable open source dependencies: Counting those

that matter. In Proceedings of the 12th ACM/IEEE International

Symposium on Empirical Software Engineering and Measurement

(Article 42, pp. 1–10). Association for Computing Machinery.

https://doi.org/10.1145/3239235.3268920.

[25] Lamb, C., & Zacchiroli, S. (2022). Reproducible builds: Increasing

the integrity of software supply chains. IEEE Software, 39(2),

62–70. https://doi.org/10.1109/MS.2021.3073045.

[26] Fourné, M., Wermke, D., Enck, W., Fahl, S., & Acar, Y. (2023). It’s

like flossing your teeth: On the importance and challenges of

reproducible builds for software supply chain security. In 2023

IEEE Symposium on Security and Privacy (SP) (pp. 1527–1544). IEEE.

https://doi.org/10.1109/SP46215.2023.10179320.

[27] Xia, B., Bi, T., Xing, Z., Lu, Q., & Zhu, L. (2023). An empirical

study on software bill of materials: Where we stand and the

road ahead. In 2023 IEEE/ACM 45th International Conference on

Software Engineering (ICSE) (pp. 2630–2642). IEEE. https://doi.

org/10.1109/ICSE48619.2023.00219.

[28] Jadala, S. K. (2024). Zero Trust Architecture and Identity Threat

Detection for Securing Cloud, IoT, and Hybrid Enterprise

Systems. International Journal of Humanities and Information

Technology, 6(04), 141-185.

[29] Zahan, N., Lin, E., Tamanna, M., Enck, W., & Williams, L. (2023).

Software bills of materials are required. Are we there yet?

IEEE Security & Privacy, 21(2), 82–88. https://doi.org/10.1109/

MSEC.2023.3237100.

[30] Stalnaker, T., Wintersgill, N., Chaparro, O., Di Penta, M.,

German, D. M., & Poshyvanyk, D. (2024). BOMs away! Inside

the minds of stakeholders: A comprehensive study of bills of

materials for software systems. In Proceedings of the IEEE/ACM

46th International Conference on Software Engineering (pp.

517–529). Association for Computing Machinery. https://doi.

org/10.1145/3597503.3623347.

[31] Potla, R. B. (2024). A SOX/ITAR-aligned global ERP template for

multi-plant manufacturers: Governance patterns and controls.

J Artif Intell Mach Learn & Data Sci, 2(2), 3222-3232.

[32] O’Donoghue, E., Boles, B., Izurieta, C., & Reinhold, A. M. (2024).

Impacts of software bill of materials (SBOM) generation on

vulnerability detection. In Proceedings of the 2024 Workshop on

Software Supply Chain Offensive Research and Ecosystem Defenses

(pp. 67–76). Association for Computing Machinery. https://doi.

org/10.1145/3689944.3696164.

[33] Sultan, S., Ahmad, I., & Dimitriou, T. (2019). Container security:

Issues, challenges, and the road ahead. IEEE Access, 7, 52976–

52996. https://doi.org/10.1109/ACCESS.2019.2911732.

[34] Rahman, A., Shamim, M. S. I., Bose, D. B., & Pandita, R. (2023).

Security misconfigurations in open source Kubernetes

manifests: An empirical study. ACM Transactions on Software

Engineering and Methodology, 32(4), Article 99, 1–36. https://

doi.org/10.1145/3579639.

[35] Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. (2022).

Challenges and solutions when adopting DevSecOps: A

systematic review. Information and Software Technology, 141,

106700. https://doi.org/10.1016/j.infsof.2021.106700

Downloads

Published

2025-09-12

How to Cite

Jadala, S. K. (2025). Software Supply Chain Security in Cloud-Native Systems: A Zero Trust Framework for Securing APIs, Containers, Dependencies, and CI/CD Pipelines. International Journal of Technology, Management and Humanities, 11(03), 171-196. https://doi.org/10.21590/

Similar Articles

91-100 of 250

You may also start an advanced similarity search for this article.