Software Dependencies & Development Tools
Parent: IA-0001
Description
This technique targets what developers import and the tools that transform source into flight binaries. Methods include dependency confusion and typosquatting, poisoned container/base images, malicious IDE plugins, and compromised compilers, linkers, or build runners that subtly alter output. Because flight and ground stacks frequently reuse open-source RTOS components, crypto libraries, protocol parsers, and build scripts, an upstream change can deterministically reproduce a backdoor downstream. Attackers also seed private mirrors or caches so “trust-on-first-use” locks in tainted packages, or abuse CI secrets and environment variables to pivot further. Effects range from inserting covert handlers into command parsers, to weakening integrity checks in update paths, to embedding telemetry beacons that exfiltrate build metadata helpful for later stages.
Mappings
EU regulation articles
Software dependencies and dev-tool components must be enumerated in the manufacturer's component identification and SBOM under Annex I, Part II, (1); poisoned dependencies are surfaced by the same SBOM discipline that documents legitimate ones.
Once a poisoned dependency is identified the manufacturer must address and remediate without delay under Annex I, Part II, (2), bounding the exploit window of dependency-confusion or typosquatting attacks.
Software-dependency compromise (primary mappings: Part II, (1)+(2) + Art. 13(5)) creates an explicit need for a CVD channel to receive reports from open-source maintainers and downstream users.
Software-dependency compromise (primary mapping: Part II, (2)) cascades to (8) — once a remediating update is available, dissemination without delay is the timing element.
Manufacturer due-diligence obligations apply to package registries, container base-image suppliers and CI/CD service providers that deliver software dependencies into the product build pipeline.
88(1)'s testing programme obligation can include supply-chain integrity checks (e.g., verification of dependency provenance, signed-build validation) that detect dependency-confusion or build-poisoning attempts before deployment.
Software-dependency testing (primary: Art. 88(1)) cascades to 88(3) — TLPT can include dependency provenance testing across the 3-yearly cadence.
Software-dependency and dev-tool compromise is supply-chain attack surface; 92(1)'s contractual information-security obligation on supplier and service-provider relationships covers these dev-pipeline touchpoints.
Dependency confusion, typosquatting, poisoned base images, malicious IDE plugins, and compromised compilers all ride supplier and service-provider relationships (registries, container registries, IDE vendors); Art. 21(2)(d)'s supplier-relationship security obligation is what constrains the trust framework.
Trust-on-first-use lock-ins on tainted packages, abuse of CI secrets, and compromised compilers are paradigmatic dev-pipeline failures Art. 21(2)(e)'s network-and-information-systems development-and-maintenance + vulnerability-handling obligation is meant to detect and remediate.
Vulnerability profile of CI runners, registries, and IDE plugin ecosystems varies dramatically by supplier; Art. 21(3) requires the entity to take those supplier-specific vulnerabilities into account when relying on third-party tooling.
Open-source maintainers, package registries and CI/CD service providers are direct suppliers under the supply-chain policy; the policy's selection and monitoring obligations apply to them as much as to silicon vendors.
Software-dependency and dev-tool suppliers (registries, foundations, CI providers) are exactly the population where Annex 5.1.6 ongoing monitoring detects upstream compromise via reports of dependency confusion, signing-key incidents and registry tampering.
Annex 5.1.7 follow-up procedures are the lever that converts monitoring signals on dependency or tooling suppliers into remediation actions (mirror updates, supplier replacement, contract amendment).
Vulnerability-handling obligations require the entity to obtain information about vulnerabilities in dependencies and toolchains, which is the metric that bounds dwell time for poisoned-dependency compromises.
Dependency confusion, typosquatting, poisoned base images and malicious build plug-ins all sit inside the build-and-tooling envelope the secure-development life cycle rules govern; those rules constrain how dependencies are pinned, mirrored, signed and verified.
Configuration management of build infrastructure (compiler versions, container base images, plug-in inventories) is the procedural lever that detects and blocks malicious modification of the toolchain that turns source into flight binaries.
ENISA controls
A documented secure development lifecycle establishes the engineering principles that govern dependency selection, build runners, and import controls.
SBOM generation against the entire software supply chain detects compromised dependencies, registries, and base images by surfacing what is actually shipped.
Supply-chain integrity controls (hash sums, supplier audits) defeat dependency confusion, typosquatting, and compromised CI/CD runners that IA-0001.01 exploits.
Cross-reference controls
Mapped by SPARTA, not curated by SafeMode Space.
- mitre-attack-enterpriseT1195.001Compromise Software Dependencies and Development Toolsrelates tomoderate
Mapped by SPARTA, not curated by SafeMode Space.
Software dependencies and development tools compromise is a software-supply-chain pattern; T0862 'Supply Chain Compromise' covers this at parent level (ICS has no specific .001-style sub-technique for dependencies/dev-tools).
Compromised dependencies and development tools produce artifacts the practice validates, but the compromise sits upstream of the validation gate and may not present as malware in the delivered image.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
CM-14 (Signed Components) mitigates IA-0001.01 by requiring signature verification on dependencies and tools entering the flight build.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
- nist-80053-rev5PM-17Protecting Controlled Unclassified Information on External Systemsrelates tomoderate
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SA-10 (Developer Configuration Management) addresses developer-side configuration controls that constrain dependency and toolchain manipulation.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SA-15 (Development Process, Standards, and Tools) addresses governance of the build environment and tooling whose subversion IA-0001.01 exploits.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SI-7(15) (Code Authentication) mitigates IA-0001.01 by authenticating build artifacts before execution.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
SR-3 mitigates IA-0001.01 by enforcing controls on dependency import paths, build tooling, and toolchain governance.
SR-4 mitigates IA-0001.01 by tracking provenance of dependencies and toolchain components used in flight builds.
Referenced in: sparta-data
Mapped by SPARTA, not curated by SafeMode Space.
T1195.001 'Compromise Software Dependencies and Development Tools' is an exact title-and-scope match to IA-0001.01 — both describe upstream-dependency tampering, poisoned base images, and compromised compilers/linkers/build runners.
SPARTA countermeasures
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Mapped by SPARTA, not curated by SafeMode Space.
Cite as SafeMode Space, IA-0001.01 (SPARTA v3.2).