Score software supply chain attack risk based on third-party dependency count, npm/PyPI package vetting, SBOM availability, and CI/CD pipeline security controls.
The Software Supply Chain Attack Risk Scorer works by applying a well-defined formula to the values you enter. Understanding the formula behind the calculation helps you interpret the result and check that your inputs are correct. Below we break down the key components that drive the Supply Chain Risk.
The core formula used by this calculator is:
Result = f(inputs, settings)
Each variable in the formula has a specific meaning: