Home / Companies / Temporal / Blog / Post Details
Content Deep Dive

Introducing Deputy: Better signal and control for software supply chains

Blog post from Temporal

Post Details
Company
Date Published
Author
Kent Gruber
Word Count
1,705
Company Posts That Month
1
Language
English
Hacker News Points
-
Post removed?
No
Summary

Deputy is an open-source, CLI-first security toolchain designed to address the challenges faced by security engineers in managing vulnerabilities across a range of targets, including repositories, container images, and VM disk images. Developed by Temporal's Security team, Deputy provides a customizable policy layer to help security teams and developers inventory, scan, triage, and control dependencies effectively. It integrates with existing systems and uses a plugin system for extensibility, offering features like deterministic supply chain analysis and execution guardrails for AI-assisted work. Deputy's policy system, written in YAML using the Common Expression Language (CEL), enables precise decision-making regarding vulnerabilities and dependencies, with policies applicable across local development, CI, and download times. Although it is still in its early stages of development, Deputy aims to provide a better signal for vulnerability management and is designed to be integrated seamlessly into existing workflows, emphasizing the importance of context and nuanced understanding in security management. The tool is freely available under the Apache 2.0 license and encourages contributions from the community to further enhance its capabilities.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.