ATALAIA
  1. Home
  2. Services
  3. Supply Chain Security
07Station 07 · Build

Supply Chain Security

Everything you did not write arrives through a port: packages, images, extensions and models. We decide what gets in, and we watch what changes.

One way in

Every package, image and extension enters through one proxy with a policy in front. The side doors are closed.

PUBLIC SOURCESYOUR PORTINSIDEdirect pullpiped to shellnpmPyPIDocker HubIDE marketplacecurl | shbinary downloadInternal proxypolicy in frontCI buildsDev laptops1234
  1. 1
    Direct pulls from public registries

    Closed. Builds only pull from the proxy.

  2. 2
    Install scripts piped to a shell

    Moved into the proxy, with a checksum.

  3. 3
    New packages and extensions

    Anything younger than 72 hours waits for a look.

  4. 4
    Maintainer or install-script changes

    Held at the proxy, released by a person.

A week at the port

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Inventory the ports

Every registry, mirror and download your builds touch.

ATALAIAWhere do your builds pull from? Every registry, every curl.

PLATFORMnpm, PyPI and Docker Hub. And one script downloads a binary.

Leaves the roomPorts: npm, PyPI, Docker Hub, 2 direct downloads

Step 2Close the side doors

Builds pull from one place, with a policy in front of it.

ATALAIAEverything goes through one internal proxy. No direct pulls.

DEV LEADWhat about that binary script?

ATALAIAIt moves into the proxy, with a checksum. Then that door closes.

Leaves the roomOne proxy, one policy in front

Step 3Watch for change

New maintainers, new install scripts, new versions of critical packages.

ATALAIAThis package changed maintainer last night and added an install script.

DEVELOPERIt's in our ledger client. We'd pull it on the next build.

ATALAIAThe proxy holds it until someone has looked.

Leaves the roomWatch list: 40 critical packages

Step 4Answer fast

When the next incident lands, you know in minutes if you're affected.

DEV LEADWhen the next big incident hits, how fast do we know?

ATALAIASearch the SBOMs for the package and you have the list of builds. Minutes, not days.

Leaves the roomSBOM per build: affected? in minutes

  • ATALAIA
  • PLATFORM
  • DEV LEAD
  • DEVELOPER

Before and after

Before

Typosquats, hijacked maintainers and poisoned updates arrive through the same door as every honest package. If anything can be pulled from anywhere, everything is in scope.

  • Builds pull straight from public registries
  • Nobody is told when a maintainer or install script changes
  • There is no list of what is actually in production
After
  • An internal proxy or registry policy for every ecosystem
  • Rules for new packages, maintainers and install scripts
  • SBOMs for what you ship
  • A watch list for the dependencies that matter most

Typical shape: Three to five weeks to set up, then ongoing watch.

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.