Penetration testing for software supply chain security: A lifecycle-oriented review of vulnerabilities, third-party dependencies, and mitigation strategies

Main Article Content

Abdiqani Cusman Abdalla
Yuchong Cui
Ihab Hussein Al Musawi

Abstract

Modern software systems increasingly rely on open-source components, third-party libraries, cloud services, containers, and automated CI/CD pipelines. This dependence improves development speed but also expands the software supply chain attack surface beyond internally written code. Vulnerabilities may be introduced through transitive dependencies, build scripts, package repositories, artifact storage, or software update channels. This review examines how penetration testing can support software supply chain security by moving beyond passive vulnerability identification toward dynamic validation of exploitable risk. A structured review approach was used to examine recent literature on software supply chain attacks, SBOM adoption, dependency governance, CI/CD security, and security testing. The findings show that penetration testing is most useful when it is mapped to specific lifecycle stages, including dependency selection, development environments, build pipelines, artifact repositories, distribution mechanisms, and monitoring. The review also identifies practical limitations, such as unclear test boundaries, incomplete dependency visibility, limited automation, and resource constraints. The paper contributes a lifecycle-oriented view of penetration testing for software supply chain security and highlights how testing can complement SBOMs, secure development practices, and continuous monitoring.

Article Details

Section

Review Articles

How to Cite

[1]
A. C. Abdalla, Y. Cui, and I. H. Al Musawi, “Penetration testing for software supply chain security: A lifecycle-oriented review of vulnerabilities, third-party dependencies, and mitigation strategies”, J. Appl. Comput. Inf. Technol., vol. 1, no. 2, pp. 108–121, Aug. 2026, doi: 10.67131/jacoit.v1i2.22.