
Bruce Gibson
November 19, 2025
OWASP Named Software Supply Chain Failures. Now It’s Time to Fix Them.
Since OWASP unveiled its 2025 Top 10, one of the most-discussed items has been A03: Software Supply Chain Failures. For many in AppSec, this came as no surprise; enterprise software’s reliance on open source has become one of its greatest strengths and arguably its biggest liability. While OWASP’s inclusion/renaming & promotion of this category signals much-needed recognition, it also raises an important question: what does “prevention” really look like in a world where vulnerabilities live inside thousands of versions of thousands of components?