Ihab Hussein Al Musawi
School of Computing, Universiti Utara Malaysia

Published : 1 Documents Claim Missing Document
Claim Missing Document
Check
Articles

Found 1 Documents
Search

Penetration testing for software supply chain security: A lifecycle-oriented review of vulnerabilities, third-party dependencies, and mitigation strategies Abdiqani Cusman Abdalla; Yuchong Cui; Ihab Hussein Al Musawi
Journal of Applied Computer and Information Technology Vol. 1 No. 2 (2026): Journal of Applied Computer and Information Technology (JACoIT)
Publisher : Global Research Innovation

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.67131/jacoit.v1i2.22

Abstract

Modern software systems increasingly rely on open-source components, third-party libraries, cloud services, containers, and automated CI/CD pipelines. This dependence improves development speed but also expands the software supply chain attack surface beyond internally written code. Vulnerabilities may be introduced through transitive dependencies, build scripts, package repositories, artifact storage, or software update channels. This review examines how penetration testing can support software supply chain security by moving beyond passive vulnerability identification toward dynamic validation of exploitable risk. A structured review approach was used to examine recent literature on software supply chain attacks, SBOM adoption, dependency governance, CI/CD security, and security testing. The findings show that penetration testing is most useful when it is mapped to specific lifecycle stages, including dependency selection, development environments, build pipelines, artifact repositories, distribution mechanisms, and monitoring. The review also identifies practical limitations, such as unclear test boundaries, incomplete dependency visibility, limited automation, and resource constraints. The paper contributes a lifecycle-oriented view of penetration testing for software supply chain security and highlights how testing can complement SBOMs, secure development practices, and continuous monitoring.