Table of Contents - X.2105 (06/2026) - Security threats targeting the software supply chain

1	Scope
2 References
3 Definitions
3.1 Terms defined elsewhere
3.2 Terms defined in this Recommendation
4 Abbreviations and acronyms
5 Conventions
6 Overview
6.1 Fundamental principles for software supply chain security
6.2 Software supply chain life cycle
6.3 Stakeholders for software supply chain
6.4 Examples of software supply chain attacks
6.5 Attacker's capabilities
7 High-level security threats and controls for software supply chain security
7.1 Security threats targeting the software supply chain
7.2 Controls for software supply chain
7.3 Mapping between high-level threats and controls for software supply chain
8 Low-level security threats in the software life cycle processes
8.1 Threats for "develop and advertise distinct malicious packages from scratch"
8.2 Threats for "create name confusion with legitimate package"
8.3 Threats for "subvert legitimate package"
9 How stakeholders can use this Recommendation
9.1 Mapping between low-level threats and stakeholders
9.2 Requirements for each stakeholder to address security threats
Appendix I – Threats taxonomy
Appendix II – Mapping between identified security threats and types of software
Appendix III – Summary of security threats in the software life cycle processes
Bibliography