Supply Chain Security
Blog →
Supply Chain Security

Level Up your Zero-day Vulnerability Remediation and SBOM Quality for a More Secure Software Supply Chain | Harness Blog

Product announcement blog detailing 3 new SCS features: SBOM quality scoring, SBOM drift detection, and real-time remediation tracking

TL;DR

  • Real-time remediation tracking enables security teams to identify affected artifacts, trace deployment pipelines, and monitor remediation progress across all environments when zero-day vulnerabilities emerge.
  • SBOM quality scoring evaluates SBOMs against NTIA minimum elements, structural standards, and sharing readiness, assigning a 1-10 score that helps teams assess supply chain visibility and identify gaps.
  • SBOM drift detection automatically flags changes in components and licenses between artifact versions, preventing newly introduced vulnerabilities from reaching production undetected.
  • Integration with Jira and project management tools streamlines remediation workflows, enabling teams to create tickets and track fixes directly from the remediation tracker.

In the relatively short time since we announced the availability of our Supply Chain Security (SCS) module, we’ve been hard at work broadening our feature set in ways that enhance customers’ ability to decisively remediate zero-day vulnerabilities with speed, and enable them to generate and manage higher quality software bills of materials (SBOMs). In this brief product update blog, we’ll have a closer look at our set newly-released SCS features: SBOM scoring, SBOM drift detection, and real-time remediation tracking.

Real-time Zero-day Remediation Tracking

Because modern applications and their software supply chains are an increasingly desirable target of cyber attackers, it is imperative to be ready and able to harden an application upon discovery of a zero day vulnerability before that vulnerability can be exploited. But this is a highly complicated undertaking given the complexity of modern application code bases and the myriad of dependencies within them.

‍

To solve these challenges, Harness SCS now features real-time remediation tracking, giving security practitioners and developers a set of powerful tools for rapidly and decisively remediating zero-day vulnerabilities– a huge advantage for mitigating security and compliance risk.

‍

Harness SCS Remediation Tracker dashboard tracking log4j vulnerability progress, impacted artifacts, and patch status

FIGURE 1: Harness SCS Remediation Tracking

‍

Artifact Enumeration

The Remediation Tracker simplifies the process of identifying vulnerable components across software deployments. By providing the component/dependency details, the tracker conducts a comprehensive scan of all artifacts. It efficiently lists down the artifacts utilizing the given component, offering a quick and accurate overview of the affected artifacts within the codebase.

Environment Visibility

The tracker goes beyond artifact enumeration to provide insights into the deployment environments impacted by the identified vulnerabilities. Once the affected artifacts are listed, the tracker offers visibility into all environments where these artifacts are deployed. This feature ensures a comprehensive understanding of the scope and reach of the vulnerabilities across various deployment environments.

Deployment Pipeline Tracing

In addition to artifact and environment details, the tracker brings transparency to the deployment pipelines associated with the identified artifacts. By attaching the environments, the tracker goes a step further to include all tied deployment pipelines used for the deployment of affected artifacts. This tracing capability allows users to navigate and take necessary actions across the entire development cycle, ensuring a holistic remediation approach.

Artifact Exclusion Mechanism

The Remediation Tracker offers a granular approach to remediation by allowing users to exclude selected artifacts from the remediation process. This mechanism ensures flexibility in the process with more control.

Deployment Status Overview

Users can easily track the overall status of remediation efforts through the tracker. It provides a clear snapshot of the number of deployments pending action and the successful deployments where remediation has been completed.

‍

These key features collectively empower organizations to swiftly and effectively address vulnerabilities in their software supply chain, ensuring a proactive and robust approach to software supply chain security.

Analysis and Summary

The tracker provides a quick summary for a concise overview of the overall remediation progress across artifacts. This summary includes informative charts that present key metrics such as the "Mean Time to Remediate," an overview of the "Remediation Status," and a snapshot of "Pending Remediations.”

Integration Capabilities

Streamlining collaboration, the tracker integrates seamlessly with Jira, enabling the creation of tickets directly from the tracker. This integration facilitates efficient communication and task management. Users can raise Jira tickets directly from the tracker, ensuring a synchronized workflow between remediation efforts and project management tools. Looking ahead, the tracker will expand its support for various project management softwares.

‍

SBOM Scoring

There is a growing necessity to have a detailed account of an application’s components and dependencies, and the Software Bill of Materials (SBOM) has become an essential element of software supply chain security. However, the wide variation in the type and completeness of information captured in a typical SBOM makes it difficult to reliably improve supply chain security and reduce risk. According to a recent IEEE study on SBOMs, only one percent of the generated SBOMs contain the NTIA “minimum elements” data for all reported components. 

‍

Given how SBOMs are commonly deficient in a variety of different ways, Harness now offers customers and users the ability to assess SBOM quality and automatically assign it an overall quality score from 1 to 10. This pays dividends for mitigating software vulnerability risks, as an SBOM can be marked as high quality, compliant, and ready to share, or it can be identified as needing improvement or further investigation on the part of DevSecOps teams. SBOM scoring is also a valuable means for software-producing organizations to determine which SBOM tools are best suited to their needs.

Harness SCS SBOM Scoring Criteria

The evaluation criteria for scoring SBOM quality falls into these categories:

‍

  • NTIA-Minimum-Elements: Assesses compliance with NTIA minimum element guidelines
  • Structural: Checks adherence to underlying specifications of SPDX or CycloneDX
  • Semantic: Evaluates the correctness of SBOM field meanings specific to their standard
  • Quality: Determines the overall data quality present in the SBOM
  • Sharing: Assesses the SBOM's readiness for sharing

‍

Harness SCS uses the sbomqs tool to evaluate SBOMs across the above categories and assign a score, upon generating the SBOM in the first place. Overall scores are shown alongside the SBOM within the ‘Pipeline Execution’ view, and can be expanded to show the individual score per evaluation criteria 

listed above.

‍

Harness SCS SBOM Score Report showing an overall score of 8.62/10 and NTIA minimum elements breakdown

FIGURE 2: Harness SCS SBOM Score Report

Automated SBOM Drift Detection

As some software artifacts often change– sometimes with each successive build– it’s expected that that artifact’s SBOM changes accordingly. SBOM drift– if left unchecked– puts organizations at risk of missing newly introduced vulnerabilities or falling out of compliance with licensing and security policies.

‍

Harness SCS now offers users SBOM drift detection capabilities for tracking changes between successive versions of an artifact, or between the artifact’s latest version and a pre-established baseline. SCS provides a detailed analysis highlighting the addition or removal of components and licenses, which greatly improves management and oversight of software artifacts. Customers can also create policies to manually review and approve any changes before moving to production. The SCS module’s SBOM drift detection supports both images and code repositories.

‍

Harness SCS SBOM Drift Report UI showing added and modified components like log4j-api and lombok

FIGURE 3: Harness SCS SBOM Drift Report

‍

Supply Chain Security, the Harness Way

More and more enterprise organizations are taking a platform approach to building out their DevSecOps practices, and a big reason why customers come to Harness is the seamless integration of critical security capabilities such as Security Testing Orchestration (STO). Harness SCS follows suit, delivering powerful OSS governance and SLSA compliance features, along with SBOM scoring, drift detection, and real-time remediation of zero-day vulnerabilities.

To learn more about Harness SCS and its expanded feature set, visit Harness Supply Chain Security

Request a demo

Contact a Harness expert

‍

← Previous:
Next: →‍

What is zero-day vulnerability remediation?

Zero-day vulnerability remediation is the process of identifying and fixing security flaws that have no available patch at the time of discovery. It requires teams to quickly locate affected systems, assess exposure, implement workarounds or compensating controls, and deploy fixes once patches become available. Speed is critical because attackers actively exploit these vulnerabilities.

How does SBOM scoring improve supply chain security?

SBOM scoring evaluates the completeness and quality of your software bill of materials against industry standards like NTIA minimum elements and SPDX specifications. A higher score (1-10 scale) indicates better component visibility, more accurate dependency data, and greater readiness for sharing with stakeholders. This helps teams identify which SBOMs can be trusted for security decisions and which need improvement.

What causes SBOM drift?

SBOM drift occurs when components, dependencies, or licenses change between successive builds of an artifact without proper tracking. Common causes include developers adding new libraries, updating package versions, or switching dependencies during development. Undetected drift can introduce new vulnerabilities or licensing risks that bypass security policies.

FAQs

Related Resources

Get Started

Get Started with Harness AI

Try the full platform free. No module restrictions, no credit card.

Kapil Digani
Director of Product Management
Kapil Digani is a product leader with 20+ years of experience in building and scaling platforms across global SaaS and enterprise domains.
kapil-digani
Kapil Digani