Modern software relies on layered architectures built from open source components, proprietary code, third-party libraries, APIs, and generative AI models. This web of dependencies forms a vast software supply chain that, without proper security, expands the attack surface.