NEWSkillSec — elevating AI Skills security from malware detection to capability auditingSkillSecLearn more →
INDUSTRY / INTERNET & ICT

Software Supply Chain Security for Internet & ICT

Dozens of deployments a day, thousands of dependencies per application, and a rising share of AI-generated code — at this cadence, security implemented as a pre-release approval step is guaranteed to fail. Security capability has to live inside the pipeline, and be fast enough to go unnoticed.

Challenges

Structural problems this industry faces

Release cadence outpaces security cadence

Continuous delivery means shipping many times a day, while traditional full scans take tens of minutes. Once security becomes a blocking step in the pipeline, security is what eventually gets bypassed.

Dependency scale beyond manual governance

Transitive dependencies in a mid-sized application easily exceed a thousand. A cross-language, cross-repository component inventory cannot be maintained by hand — when a vulnerability breaks, teams often cannot even answer whether they use the affected package.

New risk from AI-assisted development

AI-generated code may reproduce copyrighted open source fragments or reference packages that do not exist. Neither appears in any dependency manifest, so manifest comparison cannot see them.

Dual pressure from domestic and export compliance

Domestic regulation imposes code security audit obligations, while overseas business must address SBOM and vulnerability handling requirements under the EU CRA. Both standards need the same trustworthy composition data underneath.

Compliance

What regulation demands of software composition

Domestic critical infrastructure requirements

Security management of the software supply chain for critical information infrastructure is required, with code security auditing and open source risk control appearing as concrete checks during assessment.

Cybersecurity and Data Security Law

Ongoing obligations for the security of network products and services: once a vulnerability is discovered, remediation must be applied promptly and users informed — which depends on accurate knowledge of your own composition.

EU CRA

For products with digital elements placed on the EU market, composition transparency and vulnerability handling are required, with main obligations phasing in through 2027.

App store and platform requirements

Distribution platforms continue to tighten disclosure requirements for third-party SDKs and open source components, making a component inventory routine material for release approval.

Solution

End-to-end composition governance from source to deliverable

01

Incremental scanning for high-frequency release

CleanSource SCA supports incremental analysis, compressing a scan to minutes or less so security checks keep pace with multiple daily deployments rather than becoming the pipeline bottleneck.

Explore CleanSource SCA →
02

CI/CD gates with tiered policy

Embed admission gates into Jenkins, GitLab CI and GitHub Actions, setting thresholds by dependency criticality — strict blocking for core dependencies, more permissive for development tooling.

CI gate practice →
03

Analysis at the moment of AI coding

CleanCode Security Agent analyzes at the moment code is written in AI-assisted development, covering open source fragments reproduced by AI, hallucinated packages and business logic defects.

Explore CleanCode →
04

Agent and MCP admission

As AI agents begin calling tools and connecting to MCP servers, a new class of supply chain component is entering the enterprise. SkillSec replaces malware detection with capability auditing to establish admission criteria for them.

Explore SkillSec →
Practice

Deployments in high-velocity delivery

CASE 01

A leading internet platform

CleanSource SCA was wired into the CI pipeline with tiered gates set by dependency criticality: high-severity components in core services are blocked before merge, while development tooling dependencies enter an observation queue — keeping security checks from becoming a bottleneck at a cadence of multiple daily releases.

CASE 02

The security team at a large technology company

A unified component inventory now spans hundreds of repositories, allowing impact scope and remediation priority to be established within hours when an open source vulnerability breaks — turning “do we use it” from a manual investigation into a single query.

Internet and ICT customers (selected)

Baidu
Alibaba
Tencent
ByteDance
ZTE
Ant Group
Further reading

Related insights

Want to see how this works in your own pipeline?