In a world of dependency confusion attacks and compromised packages, C++ deserves built-in supply chain security. cmod delivers it.
The Supply Chain Problem
Software supply chain attacks have exploded in recent years. The C++ ecosystem is particularly vulnerable because most projects download dependencies without verifying hashes or signatures, and there's no standard audit trail.
cmod was designed with supply chain security as a first-class concern — not an afterthought.
How cmod Secures Your Build
1. Mandatory Lockfiles
Every cmod project has a cmod.lock file that records the exact Git commit hash for every dependency. When you build with --locked, cmod verifies that every dependency matches its pinned commit exactly.
This prevents silent dependency updates, version tag mutations, and resolution inconsistencies.
2. Trust-On-First-Use (TOFU)
cmod records the identity of each dependency on first use. On subsequent resolutions, it verifies the identity hasn't changed. This catches repository takeover attacks, URL hijacking, and key rotation without notification.
3. Hash Verification
cmod verify
Verifies Git commit hashes match the lockfile, source contents haven't been modified, and no unexpected files have been added.
4. Signature Verification
cmod verify --signatures
Checks that Git tags are signed with a known key, signatures are valid, and signing keys match trusted identities. Supports PGP, SSH, and Sigstore.
5. Security Policy Enforcement
Configurable policies define which sources are trusted, verification levels required, and whether unsigned dependencies are permitted. The --untrusted flag makes security trade-offs explicit.
6. Dependency Auditing
cmod audit
Analyzes your dependency tree for known security issues.
7. Software Bill of Materials (SBOM)
cmod sbom --output sbom.json
Generates a complete SBOM listing every dependency, its version, source, and verification status. Required by government regulations and compliance frameworks.
The Security Pipeline
# CI/CD security pipeline
cmod resolve
cmod build --locked --release
cmod verify --signatures
cmod audit
cmod sbom --output sbom.json
cmod test --release
Every step is auditable, deterministic, and automated.
Comparison with Other Ecosystems
| Feature | cmod | npm | Cargo | pip | Conan |
|---|---|---|---|---|---|
| Mandatory lockfiles | Yes | Yes (v7+) | Yes | No | Optional |
| Hash verification | Yes | Yes | Yes | Yes | Partial |
| Signature verification | Yes | No | No | No | Partial |
| TOFU trust model | Yes | No | No | No | No |
| SBOM generation | Built-in | Third-party | Third-party | Third-party | No |
| Audit command | Built-in | Built-in | cargo-audit | pip-audit | No |
Security Without Friction
The key design principle: security should be the default, not an opt-in. Lockfiles are mandatory. Verification is built into the standard workflow. Opting out requires an explicit flag.
When security is easy, people use it. When it's hard, they skip it. cmod makes it easy.
What's Implemented
cmod's security features are fully implemented (Phase 4 complete):
- Full signature verification — PGP, SSH, and Sigstore with
--locked --verifymode - Dependency auditing — Analyze dependencies for known security issues
- Policy enforcement — Define and enforce security requirements in CI
- SBOM generation — Full dependency inventory for compliance
Get Started
cmod init my_secure_project
cd my_secure_project
cmod add github.com/fmtlib/fmt@10.0
cmod resolve
cmod verify
cmod build --locked
cmod is open source under Apache-2.0. Help us build the most secure C++ build tool — contribute on GitHub.