Supply Chain Security for C++

In a world of dependency confusion attacks and compromised packages, C++ deserves built-in supply chain security. cmod delivers it.

The Supply Chain Problem

Software supply chain attacks have exploded in recent years. The C++ ecosystem is particularly vulnerable because most projects download dependencies without verifying hashes or signatures, and there's no standard audit trail.

cmod was designed with supply chain security as a first-class concern — not an afterthought.

How cmod Secures Your Build

1. Mandatory Lockfiles

Every cmod project has a cmod.lock file that records the exact Git commit hash for every dependency. When you build with --locked, cmod verifies that every dependency matches its pinned commit exactly.

This prevents silent dependency updates, version tag mutations, and resolution inconsistencies.

2. Trust-On-First-Use (TOFU)

cmod records the identity of each dependency on first use. On subsequent resolutions, it verifies the identity hasn't changed. This catches repository takeover attacks, URL hijacking, and key rotation without notification.

3. Hash Verification

cmod verify

Verifies Git commit hashes match the lockfile, source contents haven't been modified, and no unexpected files have been added.

4. Signature Verification

cmod verify --signatures

Checks that Git tags are signed with a known key, signatures are valid, and signing keys match trusted identities. Supports PGP, SSH, and Sigstore.

5. Security Policy Enforcement

Configurable policies define which sources are trusted, verification levels required, and whether unsigned dependencies are permitted. The --untrusted flag makes security trade-offs explicit.

6. Dependency Auditing

cmod audit

Analyzes your dependency tree for known security issues.

7. Software Bill of Materials (SBOM)

cmod sbom --output sbom.json

Generates a complete SBOM listing every dependency, its version, source, and verification status. Required by government regulations and compliance frameworks.

The Security Pipeline

# CI/CD security pipeline
cmod resolve
cmod build --locked --release
cmod verify --signatures
cmod audit
cmod sbom --output sbom.json
cmod test --release

Every step is auditable, deterministic, and automated.

Comparison with Other Ecosystems

Feature cmod npm Cargo pip Conan
Mandatory lockfilesYesYes (v7+)YesNoOptional
Hash verificationYesYesYesYesPartial
Signature verificationYesNoNoNoPartial
TOFU trust modelYesNoNoNoNo
SBOM generationBuilt-inThird-partyThird-partyThird-partyNo
Audit commandBuilt-inBuilt-incargo-auditpip-auditNo

Security Without Friction

The key design principle: security should be the default, not an opt-in. Lockfiles are mandatory. Verification is built into the standard workflow. Opting out requires an explicit flag.

When security is easy, people use it. When it's hard, they skip it. cmod makes it easy.

What's Implemented

cmod's security features are fully implemented (Phase 4 complete):

  • Full signature verification — PGP, SSH, and Sigstore with --locked --verify mode
  • Dependency auditing — Analyze dependencies for known security issues
  • Policy enforcement — Define and enforce security requirements in CI
  • SBOM generation — Full dependency inventory for compliance

Get Started

cmod init my_secure_project
cd my_secure_project
cmod add github.com/fmtlib/fmt@10.0
cmod resolve
cmod verify
cmod build --locked

cmod is open source under Apache-2.0. Help us build the most secure C++ build tool — contribute on GitHub.