AI DEFENCEBY ALTARI SYSTEMS
Menu

Coverage / Repository, build & deployment

Software supply chain security, from source to runtime.

Software supply chain security examines how source, dependencies, build infrastructure and deployment permissions contribute to the running system. AI Defence is designed to connect these stages so a finding can be understood in its actual production context.

IN DEVELOPMENTExplore the specified scope. See capability availability.

Assess the repository and its dependency inputs

The specification includes Git repository exposure, branch and release controls, lockfiles, package provenance, vulnerable dependencies and malicious packages. Secrets in current files and repository history are part of the assessment.

A dependency declared in source may differ from the version in a deployed image. Useful evidence should preserve enough component and deployment identity to establish what is affected. Unresolved identity should remain a limitation rather than being replaced by a confident assumption.

Inspect the authority of the delivery system

CI/CD workflows, build runners, artifact integrity, deployment credentials and third-party integration privileges are explicit areas of review. A runner can become a sensitive trust boundary when it holds keys or can publish software to production.

Branch controls and review requirements describe one part of the system. The ability to change a workflow, substitute an artifact or use an overprivileged integration can introduce separate paths. The assessment should explain the relationship between repository permissions, build authority and release authority.

  • Identify exposed repositories and unnecessarily broad integration access.
  • Examine dependency and image provenance where evidence is available.
  • Review secrets across source, history, build configuration and deployment.
  • Record gaps in artifact identity or deployment traceability.

Fix the source of the risk, then check the deployed result

A proposed repair might update a dependency, tighten a workflow permission, revoke an exposed credential or strengthen a release control. Each action requires a bounded plan and appropriate review. A code change and its deployment are distinct events.

Verification should confirm that the intended correction reaches the running environment and that relevant tests still succeed. AI Defence’s ongoing scope includes new repository and dependency risks, while Remedy’s software repair discipline provides a related model for exact-state repair and deterministic gates. The cross-product integration must be confirmed before it is relied upon operationally.

Questions answered

Is a clean repository scan enough?

No. Build runners, deployment credentials, artifacts and the running workload can introduce different risks. The specified assessment considers the chain of trust between them.

Will repository scanning automatically rewrite code?

The initial assessment is observational. A source change requires a separate governed repair workflow and authorisation for the relevant repository and deployment actions.

Start with understanding

What does your environment need to defend?

Discuss the assessment scope, current capabilities and the control you need with Altari Systems.

Talk to Altari