Building Software Supply Chain Security From the Catalog

Building Software Supply Chain Security From the Catalog

Software Supply Chain Security is the job of knowing and trusting what goes into a build — dependency inventory, SBOMs, license checks, artifact signing, and provenance across the release pipeline.

16 providers on the network offer it, publishing 514 APIs between them.

Sixteen is a small number for a category that every regulated industry now has a policy about. It is not a mature vendor market; it is a handful of companies and a lot of open-source tooling.

The cohort

Band Provider APIs Score
Exemplar GitHub 384 72.4
Exemplar Anchore 6 66.5
Strong Amazon License Manager 1 64.9

Also in the cohort: Amazon CodeArtifact and Livepeer.

Note the shape. GitHub publishes 384 APIs and scores 72.4. Anchore publishes six and scores 66.5. The gap is six points for a sixty-fold difference in surface area, which tells you the rubric is measuring description quality rather than volume — and that a focused vendor can sit alongside a platform.

A build path

Inventory first. GitHub’s dependency and SBOM surfaces are where most estates already have the data, whether or not anyone is reading it. Start there because the integration cost is near zero.

Scan and gate. Snyk publishes 48 APIs including a dedicated AiBom API — an AI Bill of Materials, covered separately this week — alongside SBOM, Findings, Issues and Container Image endpoints. This is where a policy becomes a build failure instead of a report.

Sign and attest. Artifact signing and provenance is where the open-source stack is stronger than the commercial one. The catalog’s coverage here is thinner than the category deserves.

Export the evidence. Audit Logs and Issues Export APIs are the difference between having supply-chain security and being able to prove it to an auditor. Both are unglamorous and both are the ones that get skipped.

What changed underneath this category

SBOMs became a compliance artifact rather than an engineering nicety, and then AI arrived and added a second inventory problem. What model, what weights, what training data, what license — the AIBOM question — is the SBOM question asked about a different kind of dependency, and the tooling is roughly where SBOM tooling was in 2020.

Sixteen providers is a market that has not caught up to its mandate. The regulatory pressure is already here; the vendor ecosystem is not.

Takeaway

514 APIs across 16 providers, anchored by GitHub for inventory and Anchore and Snyk for scanning — with signing and provenance still thinner than the category needs. If you are building this today, you are assembling it from a small number of parts and filling the gaps yourself.

Browse the use case at apis.io/use-cases/software-supply-chain/.

← Biotechnology on APIs.io: 1,060 Providers and Fewer Than One API Each
Profiling Salesforce: 294 APIs and the Most Balanced Scorecard in the Catalog →