Secure software supply-chain architecture

c4v1

/01 Views

Architecture landscapec4
Focused dependenciesc4

/02 About

Reference model connecting the principal responsibilities, information and governance of secure software supply-chain architecture.

Purpose: establish an editable, technology-neutral secure software supply-chain architecture baseline. The model defines seven distinct responsibilities, their dependencies, and the architecture boundary so teams can replace generic reference nodes with their own assets and accountabilities. How to use: begin with the Architecture landscape view; identify accountable owners, replace each reference node with an organization-specific element, verify directions and interfaces, and enrich with constraints, quality attributes, data classifications and operational evidence. Use the Focused dependencies view for design review. Validation and trade-offs: this is a reference starting point, not a claim of compliance or implementation completeness. Check domain-specific standards, responsibility segregation, lifecycle assumptions, recovery targets and governance decisions before promoting it to a target-state architecture.

Published by Lattix · 7 elements · 6 relationships · validated on publish

/03 Contents

Role
Developer
Application
Source repository, Production application
Application Component
Trusted build runner, Security verifier, Deployment verifier
Data Store
Signed artifact repository
Secure software supply-chain architecture · Architecture hub · Arq