Software Supply Chain Security Tooling
Introducing Deputy: Better signal and control for software supply chains

Introducing Deputy: Better signal and control for software supply chains

8/3/2026

What this post added

This post introduces Deputy, a new open-source toolchain for software supply chain security. It details the challenges of vulnerability management, including false positives and the need for context-aware analysis. Deputy's architecture is described, highlighting its plugin system, package extractors (leveraging OSV-SCALIBR), and data enrichment capabilities. The post elaborates on the policy system using CEL, providing examples for exploit signal gating, vulnerability SLA enforcement, and lookalike package warnings. It also covers Deputy's remediation features (`deputy triage`, `deputy fix`), sandboxed execution (`deputy exec`), and download-time proxy (`deputy proxy`).

Read the original post ↗