Abstract
- Containerization has become a widely adopted ap-proach for running contemporary software services, with itsingenious layering of Free Open Source Software (FOSS) librariesand packages. The security of containers heavily relies on theintegrity of their underlying dependencies, making vulnerabilityassessment a critical focus for security professionals. However,the landscape has evolved, and recent software supply chainattacks have illuminated a pressing need to shift the focus beyondindividual vulnerabilities and delve into the overall securityof their supply chain. In this paper, we embark on a data-driven analysis of container threats by examining the securitycharacteristics of software supply chains in their open sourcedependencies. Leveraging a comprehensive dataset of containersfrom Docker Hub, our study employs Software Supply Chainmetrics like the OSSF scorecard and Software Bill of Material(SBOM) tooling to compile dependency lists. The analysis deliversvaluable insights to the security community, empowering themto adopt more effective measures in thwarting and mitigatingsoftware supply chain attacks, thereby enhancing the resilienceof modern software services.