Software Supply Chain: What to Expect in 2025 – From the Source EP5
What’s really happening in the world of software security, and what new challenges will arise next year? In this webinar, Sonatype CTOs Brian Fox and Ilkka Turunen highlight the key trends, challenges, and innovations shaping the market today and discuss what they have their eyes on going into 2025. Gain a deeper understanding of the current landscape and start considering next year’s evolving threats and opportunities in software development and supply chain management.
Transcript
Well, hey everybody. Welcome to another episode of From The Source with your host, uh, me, Ilka Turnin. And Hi, I'm Brian Fox.
And, um, uh, today, Brian, uh, guess what, what the year's over. That's what, um, so, uh, so, um, I know, I know it feels really weird even to say that, but, uh, so it has occurred that, um, we are at the end of, uh, end of the calendar cycle, um, you know, turkeys in our future and, uh, gifts and all, all that sort of stuff. And, uh, the theme for today's episode is a little bit special because what we wanted to do, um, was really to, um, uh, talk a little bit about, uh, uh, what does the crystal ball say, uh, is gonna happen in the industry, uh, next year.
So, um, um, so, um, uh, with that, Brian, uh, let's, let's do a quick recap. 2024, huge amount of supply chain issues. We had big deals like Ex Exit, we had, uh, small deals, uh, huge hacks like, um, snowflake.
We've got one going on right now that's, uh, in the news with, uh, lots of advanced persistent threat actors. Mm-Hmm. Um, research revealed that open source being consumed ever more than ever before.
AI explosion, all of that sort of stuff. So, let's just ask a very simple question. Where is it all leading?
Like, what are we gonna all have to care about next year, uh, with all of that? Um, and I'm gonna lead you on with an idea. Exed feels like it's a bit of an omen, doesn't it?
Uh, yeah. Um, you know, like I I, I've said this before, that, uh, the XEU utils, the, the long running, you know, attempted takeover of a, of a critical component, um, that was accidentally discovered earlier this year is not a single incident. There has been one more disclosed, and I'm aware of at least one more that is still being investigated.
So, um, so I think the, the headline is, uh, everybody feels like we found the thing, we got lucky and we moved on with life. Um, the rest of us are looking at it going, no, these things are still happening and we just haven't discovered them yet. They will turn up at some point in the future.
Um, hopefully we catch 'em before they're, they're massively impactful, but, um, but I'm not betting on all of that. So, so that's certainly a, a big thing that, that leads in that direction. Um, you know, as you know, over on your side of the pond, they just recently, you know, officially published the CRA and the PLD into, uh, what your book of laws, I forget what it's called, The official Journal of the European Union, which, uh, there you go, requires the starting gun of, uh, maybe the implementation period.
That's right. So they published A CRA on the, uh, uh, on, it'll take effect exactly on the third anniversary of the log for Shell, um, incident. Right.
And, and that has a, a what, a two year phase in period, it becomes, uh, effective 2027. But there are some, uh, some things that take effect in 2026, right? So, Yeah, so there's a, there's sort of a three year implementation period for most of the obligations.
So, so for those of you who might not know what we're talking about, CRA Cyber Resilience Act, we have a whole episode about, uh, about regulations. Long story short, minimum cybersecurity standards for software, you have to follow them and get it self certify or get certified depending on a little bit on what kind of product you're building in order for your product to be available in the European Union market if it's a software product. So, so, um, uh, with that, the implementation time wise is a little bit of, sort of jiggling there as far as I understand.
But, uh, yeah, 2026, uh, end of 2026 when they are expecting, uh, expecting, uh, you to be able to monitor for any new security vulnerability affecting your software and be able to, uh, able to, uh, let your customers and the authorities know about it if, if it affects you. And in 2027, the wider sort of minimum security requirements, including the certification, uh, that you followed them, kind of falls into action. So for just quite A lot, Quite frankly, quite a lot of things to get done, uh, in less than three years.
Yeah. So I think, you know, because there's a, a couple year phase in, and frankly, the specifications and standards that, that the, uh, the legislation depends upon aren't yet fully hammered out. Um, no, totally not.
You know, this next year, um, you and I are both gonna be involved and a lot of working groups both at Eclipse as well as, uh, open SSF, there's multiple groups that many of the open source foundations are participating in to help, uh, represent, uh, the, the overall community in terms of defining these standards and specifications. So a prediction, which feels barely like a prediction and more like a fact, is that a whole bunch of us in this industry are gonna be working together over the next, at least 12 months to help try to solidify those recommendations that would then become, um, you know, the, the, the leverage points for the legislation that's, that's already starting, right? Um, but I think there's going to be a lot of that, um, next year, I think.
0 standard, which true bases in, in March of 2025, right? So it was published last March. Um, and some of the provisions in there require things like software bills and materials and, and a lot of the similar things that we see in these legislation.
I remember when it came out and I, around, you know, maybe February or something last year, and I was like, oh, wow, great, that's gonna take effect. And it's like, oh, we have to wait another year for it. So we've been busy doing other things and the, and the calendar moved on, but March is not that far away.
And so I think actually there is a potential for the PCI requirements to drive more action across the, the ecosystem generally, because financial, uh, uh, FinTech type companies tend to be more progress progressive on this, uh, area anyway. Um, and, uh, then as, for example, as opposed to big, uh, government, um, integrators, things that would be subjected to the executive order SBO M standards, right? Those things take much longer because the procurement process, you know, they might be on a 10 year contract, so it wouldn't affect some of these things until, you know, the next up of their contract kind of thing.
But the PCI standard, I don't believe has that, that long tail to it. So my prediction is we're gonna see some action. There's probably gonna be some people who haven't been paying attention and come March, um, that can be scrambling to try to figure this out.
Um, but I, I, I'm looking forward to the fact that we finally will have something with a, a bit of teeth in at least one of the industries next year. I, I think you're absolutely right. And I think actually, you know, we're gonna follow the exact same pattern that we followed with GDPR, right?
You know, the, the about 20% of the population remembers about it before hand starts. Process starts work about three months before it starts biting. We're gonna start seeing some scrambling.
Sometimes we even see deferred deadlines. So for example, with NI two, which is sort of a precursor to, uh, CRA, you know, in terms of it puts some security requirements already that was actually supposed to be enforced a month ago. Mm-Hmm.
But most of the European Union nations haven't passed the laws. They, they're nowhere near being able to actually enforce it at this stage. So a lot of that has been delayed sort of into next year.
So I think what we're gonna see with the CRA is a little bit of a different picture. 'cause there's so much collaboration to your point, like the, the working groups are forming, there's about 58 standards, if I remember correct. Mm-Hmm.
Um, that are gonna be, that are gonna be defined, uh, with industry, with, uh, regulators, et cetera, that kind of define the sort of which industry should be covered with more sort of strict sanctions, what are the minimal and technical requirements, et cetera. It's going to be quite specific. Um, and so I do honestly think that, um, it's going to set a sort of minimum floor of what application security, software security and supply chain security are gonna look like.
Mm-Hmm. Um, globally, because, you know, it's, it's such a big market that it's, you know, just like DDPR is gonna, you know, as much as we all like clicking on those cookie uh, bars, they are going to set that minimum bar of, uh, yeah. Uh, of, um, regulation.
So in that sort of sense, in that sort of sense, I think next year the prediction to me is that we're gonna see the front runners start putting that into place. We're gonna see some frameworks that describe how that's gonna come, uh, come out. And I think we're going to get, get to see maybe even some early, to your point, you know, PCI is a good example, you know, if you don't get the certification, you're not gonna be able to process credit card payments.
That's a big material impact. Mm-Hmm. Um, and in the finance world, we also have something called Dora that's gonna kick in January.
Um, already seeing, uh, the effects kind of happening behind the scenes where businesses are kind of, sort of being asked a lot of Dora related questions. I think next year is gonna be a mad scramble for many places just to kind of come to terms with the fact that, uh, those sort of, uh, requirements are, are already sort of, kind of coming to play one way or the other. Yeah.
Yep. I mean, I think, you know, the other, the other thing that's inevitable, you know, on this side of the pond is, you know, we have a new administration coming in and, you know, as we record this, we're still not sure how that's gonna unfold, especially as it relates to csa. You know, we know that, um, CSA has been a little bit under fire, uh, for, for, for some of that stuff around the election security.
Uh, we know that, um, miss Easterly is stepping down as is typical with, uh, appointed, uh, heads of the departments. Uh, we don't know who will be replacing it. I am legitimately concerned, however, because I feel like over the last, especially the last two years, um, you know, CISA has done a great job building up, uh, some of their, their staff, uh, with people who are, um, you know, from the open source community who understand the nuance of all these things and have, and they've, they've built great relationships, um, with the different foundations and individuals that never existed before.
You know, prior to log for Shell, the government was essentially nowhere to be found, as far as I'm concerned. And I, and I can't even count how many, uh, different sessions and, um, and, uh, working groups and things like that. I've been part, been a part of, uh, spearheaded by CIS over the last two years.
So I am, I am very concerned that we will lose a lot of the momentum that has been built there. Um, hopefully that doesn't come to pass, but, um, but, but it might, and, um, you know, related, I think we should expect that the, the new administration will be certainly more business friendly, um, than regulation friendly. I don't think that's, um, controversial.
I don't think that's a Secret at all. Yeah. Yeah.
I think that's fairly, fairly obvious on, on its face. And so as a result, I think that means we're even less likely to see, um, our own versions of things like CRA and even, uh, the software liability re reform that I've been kind of, kind of pushing, you know, we saw in, um, last year's tenure, uh, ONCD, you know, national cyber strategy, the right kinds of words, recognizing the importance of the open source community, but not trying to, you know, hamper innovation and, and walking a fine line. I'm afraid all of that gets ripped up and thrown out and replaced with who knows what.
Um, and, and as fortunate as it is to say it, I think, you know, we're going to be dependent upon, um, some of these European Union legislations in the, the short term, uh, and the PCI to try to lead the way, you know, just like we saw with the GDPR, um, you know, it's super annoying for me because every website I I hit these days is nagging me about the cookies. Um, even though I don't live in the European Union, that's because software is a global market. So pretty much any, any company that, um, that, that is not a niche player is going to have to be following the best practices laid out by the CRA, uh, and the PLD.
Um, and that's going to make the software better. That's not like they develop necessarily software separately. They don't build it differently for Europe than they do the rest of the world.
And so I think that the, the, uh, trickle down effects of that will, uh, ultimately level up everything, even though we don't, uh, necessarily have our own, um, legislation over here. Well, well, let me talk about that court a little bit more, uh, just as sort of way of a logical exam, uh, logical sort of thinking as we're, as we're talking here. Right?
Um, so one of the key promises, 2 trillion cut from our public spending in the us, um, one element that we all in our profession in, in, in cybersecurity rely on is the National Institute of Standards, uh, and the NVD. Right? And this year, the NVD suffered through sort of a drought of, of funding, right?
And as a result, uh, even right now, I think they have a backlog of about 19,000 CBEs that, uh, have not been enriched enough, uh, for it to, uh, be published as a, uh, as a sort of fully accosted, uh, uh, vulnerability enumeration. Nearly all of our cybersecurity infrastructure relies on the NVD, uh, more or less. So if we, you know, for whatever reason the funding to that program is cut, we are gonna have to, uh, have our hands full in, uh, as an industry trying to figure out how to backfill that sort of valuable source of information we do.
Um, that's of course, you know, uh, we don't know anything about what the administration is gonna do, what's gonna happen there and, and how they're thinking about it. But I think it's a pretty safe bet to make that that backlog is probably not gonna disappear anytime soon either. Um, and yeah, I don't, I, I don't think so.
I mean, the number of these new things is, is increasing as we've shown in, in the stats year over year, that, um, you know, uh, unless there, there is a high potential for collateral damage, certainly, you know, if, if funding is cut, you know, I think CISO CISA was kicking in some to help help, uh, get that contract going Again, if, if funding is cut there or the department is merged into something else, yeah, there could be some collateral damage there. Um, I suspect though, you know, that was a multi-year contract with the vendor coming in to help, uh, lift the NVD backlog out. That probably doesn't go away, but, you know, if, if they shut down the department, like we like to do with the shutting down the government, any, any, any bets are, are off at that point.
So who knows. Yeah. Um, it is a Risk.
Exactly. Yeah. But I, I, I think, um, that just underlines really the, the, uh, sort of perspective of look, you know, we also need to think about, you know, luckily the CRA actually funds the European equivalent in EA to start up a European, uh, vulnerability database.
So we're probably gonna see the emergence of sort of various regional catalogs and finding out ways of how we are gonna mee that. It's gonna be a big thing. The reason why I say that it's a prediction though, is, um, it's going to cause chaos, uh, in incident management if we don't figure out, or at least be aware of that potential risk.
Anyway, that's a jolly prediction. Why don't we move on to another one. Um, let's talk about something fun.
Let's talk about ai. Uh, you know, what's your predictions about AI next year? What's ai?
I don't know what you're talking about. Yeah, Yeah. It's, uh, it's a little word.
It starts with an A ends in an i I Mean, regards, uh, your homework and, uh, your Christmas cards too. Yeah, I mean, I think, I think we're Clearly we're gonna continue to evolve there. Is it gonna evolve as quickly as it did in the last couple years?
Maybe not. Um, you know, we might be entering a little bit of a trough of disillusionment type of type of thing, um, as everybody, you know, gets over the hype and then tries to figure out what the new norm is and how to, uh, uh, best leverage this. Um, clearly, um, you know, there's lots of startups around ai.
com boom, you know, so AI's not gonna, not gonna go away, but all the startups trying to, you know, trying to cash in on that, it's gonna be interesting to watch. Um, you know, but as, as the, the usage and the workloads mature, I think, yeah, we're gonna start to see some of the, the promise of that. We may also, you know, as a society and a and economy start to have to reconcile, you know, the impact to, um, various jobs that become redundant to good enough ai.
Um, it, it's already happening in some places, but I suspect it will happen at a broader scale, at least over the next 12 to 24 months with potentially large ramifications for society as that happens. Yeah, for sure. I mean, uh, there's a, this Swedish company could, by the name of Clon does, um, uh, online payments.
They pretty openly said that they are cutting 50% of their entire staff, and they expect it to be fully backfilled, uh, with ai, and they already did it in their customer support. So definitely, I think it's an understatement to say that it's gonna have some ramification. I think it will, it will definitely have some.
I think, uh, for me, I take a little bit of, a little bit of more sort of practical approach to it. I think that we're gonna see more of, uh, AI assisted, uh, malware generation. We are already seeing it today, of course.
In fact, I think about a year ago, a year and a half ago, we, we discovered what we think is arguably the first, uh, chat GPT generated piece of open source malware, uh, within the software supply chain, I think was an MPM package. And it was pretty clear because one of our security researchers actually managed to reproduce the code one-on-one by prompting Jet GPT in Spanish, uh, if you remember that one. Mm-Hmm.
Yeah. So, you know that that's already a given, you know, for, you know, about 60% of code on GitHub is being produced with copilot. Um, I'm pretty sure that 60% of malware is also being produced by either copilots or, you know, broken, uh, down, um, um, pro.
Yeah, There, there's that aspect. And then there's the fact that it makes it much easier to, you know, effectively dos open source maintainers with plausible looking pull requests and or bug reports that, you know, um, on their face look real, but are garbage. And then just basically filibuster them with crap so that they can't actually do good work.
That I think is already happening. If it happens more, that's gonna be very problematic for, for the ecosystem at large. Yeah, and I think, I think another sort of groundbreaking ramification is, is that, um, you know, the infrastructure on ai, the supply chain that's formed around it, the tooling, the sort of the ways to integrate it into your software, the actual model files themselves are already subjects to sub software supply chain attacks.
You see the exact same phenomenon happening as G in normal, uh, you know, dependency land. And I think that's just gonna get worse. You know, the, the adoption curve is so exponential, it'll be a surprise if we don't see sort of the first major AI targeted supply chain attack next year.
Yeah, for sure. And you know, we were just talking about this earlier this week, but, you know, we're seeing a lot of organizations when we do analysis of their applications, we're finding these open source models in places where they vehemently deny, we're not using ai, our developers are not using ai. And you know, I kind of laugh because 12, 13, 14 years ago, um, we would talk to people at organizations say, we're not using open source.
Meanwhile, the developers are pulling down, you know, 60,000 components from Maven Central a year. Um, and so there, there is clearly, uh, a repetition there that there's a disconnect in what's actually being used versus what they're supposed to use and what the, the leaders think are being used. So I suspect that that will get more attention, um, in the next year, uh, as, as people gr mature, that, that, um, not only their use, but their governance of what's going on as well.
Yeah. I, I, I really think so. I think, you know, we'll both see, uh, sort of rapid maturation of the engineering practices of integrating ai, but we're also gonna see people targeting that exact process, uh, because that's exactly what happened to open source, you know, it became popular grassroots pool.
It's just too big to stop. Like, you know, if you, if you think that your developers aren't using or playing around with ai, I think you're deluded at this point. Everybody's, everybody's doing it and playing around with it, and that's why, you know, new features will come out.
But as a, as a shadow phenomenon, that means that there's sort of urgency and importance to getting control of what the dependency management of, of those components are, uh, and getting them under the sort of software factory umbrella that you might have, uh, or engineering platform umbrella you might have already. Yep, yep. So maybe, maybe, um, maybe we leave it at there.
Um, yeah, covered a lot of ground. Uh, Yeah, we, we, uh, I feel, uh, I feel a lot surprisingly depressed with, with that, but, you know, I think it's more good than it is bad, and it's our joke to be thinking about the depressing stuff, so, Mm-Hmm. Well, Brian, I mean, we space you very much, it's hard not to be, it's hard not to be jaded after a while because we see all these things and, you know, it's hard to drive action, but we get there eventually kicking and screaming.
And I think these, uh, regulations are really a sign that, um, you know, e even if different countries move a little bit in different direction, I think the general direction of travel, no matter where you look, it's going to be towards, we are going to be much more standardized than we have ever been in the Mm-Hmm. In the past, uh, and regulated. So with that thoughts, uh, Brian, thank you very much for this year.
Uh, looking forward to a very interesting 2025. Who knows what we'll find on. That's Right.
See you next year. A good one.

