A new open-source Software Factory Security Framework (SF²), developed by Julie Davila of GitLab, has been introduced to help organizations strategically scale their security operations. The framework emphasizes resource allocation over simply increasing staff and outlines five core security responsibilities for software-producing organizations: supply chain security, process stewardship, runtime protection, third-party risk management, and continuous learning. SF² provides actionable guidance for each area, such as dependency monitoring and pipeline security controls, aiming to improve both security outcomes and business alignment.
Simultaneously, the adoption of Software Bill of Materials (SBOMs) remains a contentious issue in the software industry. While SBOMs are recognized as essential for addressing supply chain security, their practical implementation is hampered by ecosystem complexity and incomplete coverage, especially in open-source projects. Companies like Docker have integrated SBOMs and provenance verification into their container images, but many organizations still struggle to generate comprehensive SBOMs for all software components. Recent updates from CISA have increased requirements for SBOM completeness, highlighting the ongoing challenges and ambivalence within the industry regarding their effectiveness.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Julie Davila of GitLab developed the open-source Software Factory Security Framework (SF²) to help organizations scale security operations strategically through stewardship, posture assessment, and investment planning.
Docker incorporated complete SBOMs alongside provenance claims meeting SLSA Level 3 in its Docker Hardened Images, signaling a concrete vendor implementation of software supply-chain transparency controls.
The Linux Foundation released an update to the Supply-chain Levels for Software Artifacts framework, identified as SLSA 1.2, as part of broader efforts to strengthen software build-pipeline security.
CISA updated its software bill of materials guidance to require machine-readable formats such as SPDX or CycloneDX, reflecting a push toward more standardized SBOM production and exchange.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.