Step 1Inventory the ports
Every registry, mirror and download your builds touch.
ATALAIAWhere do your builds pull from? Every registry, every curl.
PLATFORMnpm, PyPI and Docker Hub. And one script downloads a binary.
Leaves the roomPorts: npm, PyPI, Docker Hub, 2 direct downloads
Step 2Close the side doors
Builds pull from one place, with a policy in front of it.
ATALAIAEverything goes through one internal proxy. No direct pulls.
DEV LEADWhat about that binary script?
ATALAIAIt moves into the proxy, with a checksum. Then that door closes.
Leaves the roomOne proxy, one policy in front
Step 3Watch for change
New maintainers, new install scripts, new versions of critical packages.
ATALAIAThis package changed maintainer last night and added an install script.
DEVELOPERIt's in our ledger client. We'd pull it on the next build.
ATALAIAThe proxy holds it until someone has looked.
Leaves the roomWatch list: 40 critical packages
Step 4Answer fast
When the next incident lands, you know in minutes if you're affected.
DEV LEADWhen the next big incident hits, how fast do we know?
ATALAIASearch the SBOMs for the package and you have the list of builds. Minutes, not days.
Leaves the roomSBOM per build: affected? in minutes
- ATALAIA
- PLATFORM
- DEV LEAD
- DEVELOPER