Software Supply Chain Glossary
A comprehensive collection of terms, concepts, and definitions related to software supply chain management.
P
Package Manager
A tool that automates the process of installing, upgrading, configuring, and removing software dependencies in a consistent manner.
Permissive Licenses
Open source licenses that impose minimal restrictions on the redistribution and use of software, allowing for incorporation into proprietary products with few requirements beyond attribution.
Policy as Code
Policy as Code is the practice of defining and managing compliance policies in code form, enabling automated enforcement, version control, and consistent application across development environments.
Provenance
Metadata that describes the origin, creation process, and supply chain journey of a software artifact, enabling verification of its authenticity and integrity.