Select an image and press Start pipeline
Clean image Compromised image Checkpoint passed Checkpoint blocked
⚠ Couldn't load the 3D engineThree.js failed to load from the CDN. Check your connection and reload.

Container Supply Chain Security Pipeline

This simulator walks a container image through a real DevSecOps CI/CD pipeline — code, base image, dependencies, build, registry and cluster deployment — pausing at each of the four checkpoints teams actually use to keep a supply chain trustworthy: vulnerability scanning, SBOM generation, cryptographic image signing and Kubernetes admission control. Switch between a clean build and one compromised by an unauthorized dependency to see exactly which checkpoint catches the problem, and which ones a stealthy, SolarWinds-style build-time compromise can slip past.