Penetration testing for software supply chain security: A lifecycle-oriented review of vulnerabilities, third-party dependencies, and mitigation strategies
Main Article Content
Abstract
Modern software systems increasingly rely on open-source components, third-party libraries, cloud services, containers, and automated CI/CD pipelines. This dependence improves development speed but also expands the software supply chain attack surface beyond internally written code. Vulnerabilities may be introduced through transitive dependencies, build scripts, package repositories, artifact storage, or software update channels. This review examines how penetration testing can support software supply chain security by moving beyond passive vulnerability identification toward dynamic validation of exploitable risk. A structured review approach was used to examine recent literature on software supply chain attacks, SBOM adoption, dependency governance, CI/CD security, and security testing. The findings show that penetration testing is most useful when it is mapped to specific lifecycle stages, including dependency selection, development environments, build pipelines, artifact repositories, distribution mechanisms, and monitoring. The review also identifies practical limitations, such as unclear test boundaries, incomplete dependency visibility, limited automation, and resource constraints. The paper contributes a lifecycle-oriented view of penetration testing for software supply chain security and highlights how testing can complement SBOMs, secure development practices, and continuous monitoring.
Article Details
Section

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
All articles published in this journal are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0).
Authors retain copyright and grant the journal the right of first publication.
This license allows others to share, copy, redistribute, and adapt the work for any purpose, even commercially, provided that appropriate credit is given to the original author(s) and the source. Any derivative works must be distributed under the same license as the original.