Introducing Deputy: Better signal and control for software supply chains
Blog post from Temporal
Deputy is an open-source, CLI-first security toolchain designed to address the challenges faced by security engineers in managing vulnerabilities across a range of targets, including repositories, container images, and VM disk images. Developed by Temporal's Security team, Deputy provides a customizable policy layer to help security teams and developers inventory, scan, triage, and control dependencies effectively. It integrates with existing systems and uses a plugin system for extensibility, offering features like deterministic supply chain analysis and execution guardrails for AI-assisted work. Deputy's policy system, written in YAML using the Common Expression Language (CEL), enables precise decision-making regarding vulnerabilities and dependencies, with policies applicable across local development, CI, and download times. Although it is still in its early stages of development, Deputy aims to provide a better signal for vulnerability management and is designed to be integrated seamlessly into existing workflows, emphasizing the importance of context and nuanced understanding in security management. The tool is freely available under the Apache 2.0 license and encourages contributions from the community to further enhance its capabilities.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.