Skip to main content
A Singapore Government Agency Website How to identify
Official website links end with .gov.sg
Government agencies communicate via .gov.sg websites (e.g. go.gov.sg/open). Trusted websites
Secure websites use HTTPS
Look for a lock () or https:// as an added precaution. Share sensitive information only on official, secure websites.

Software Supply Chain

Controls to prevent tampering and improve the integrity of the software supply chain.

Last updated 4 March 2026

SC-1: Code Repository

Control Statement

Control Recommendations

Risk Statement

SC-2: Commit Signing

Control Statement

Control Recommendations

Risk Statement

SC-3: Peer Review

Control Statement

Control Recommendations

Risk Statement

SC-4: Dependency Manifest Version Pinning

Control Statement

Control Recommendations

Risk Statement

SC-5: Build and Release Process

Control Statement

Control Recommendations

Risk Statement

SC-6: Dependency Installation during Deployment

Control Statement

Control Recommendations

Risk Statement

SC-7: Software Artefact Signing

Control Statement

Control Recommendations

Risk Statement

SC-8: Software Artefact Signature Verification

Control Statement

Control Recommendations

Risk Statement

SC-9: Internal Code Collaboration and Sharing

Control Statement

Control Recommendations

Risk Statement