Policy & Compliance

Introducing CodeSupply

Open data, decentralized and distributed access, federated trust: how CodeSupply rethinks software supply chains metadata

Seminar 4

16:2015 mins13/11/2026

Software supply chains security depends on accurate metadata: origin, licensing, vulnerabilities, and project health. That metadata is scattered across package registries and vulnerability databases, often conflicting or outdated, and stored in multiple incompatible data formats. Proprietary systems provide no reproducibility, traceability, or auditability, even as regulators and security teams demand exactly that, and development teams require actionable, accurate, and current data to improve their security posture.
CodeSupply is a new Horizon Europe project building an open, federated data catalog to fix this with accessible access to current, correct, comprehensive metadata. Using PURLs (Package-URLs) as universal identifiers for software packages, it aggregates and curates software metadata from distributed, authoritative sources across heterogeneous ecosystems, assembles it into reference, curated data sets, and federates it in a unified and decentralized catalog distributed as open data under an open source license.
This talk introduces CodeSupply’s architecture and open data sources, and how it fits into existing software supply chain security and compliance workflows, that are primarily FOSS-centric. You’ll leave knowing how to plug into the project, whether as a data consumer, a contributor, a curator, or an organization looking for digital sovereignty over its own supply chains metadata.

BENEFITS TO THE ECOSYSTEM

* Unified, distributed and open source of truth for metadata
Understanding how CodeSupply aims to consolidate scattered, conflicting origin, license, vulnerability, and project-health data into one distributed and federated catalog, reducing the duplicated effort of cross-referencing multiple registries, duplicating scans, and code reviews to ensure we can all share and access effective origin, license, security, and health open data for all FOSS projects.

* Auditability over black-box, proprietary data
Learning how an open, traceable, reproducible approach to software supply chains data addresses the core weakness of proprietary systems, with an opaque approach to curation. This is relevant for any team facing regulatory requirements (like CRA) that demand verifiable, curated compliance data to assess supply chain risks such as exploited vulnerabilities in under 24 hours. When automation is the only way, then correct, open data is the way towards enabling this automation.

* PURL-based supply chains interoperability
Understanding how using Package-URLs as universal identifiers lets CodeSupply tie into the broader standards ecosystem (ScanCode, ClearlyDefined, vulnerability databases) rather than creating yet another siloed format, when PURL is emerging as the leading identifiers across CVE, OSV, CSAF, CycloneDX, SPDX and OpenVEX formats for vulnerabilities, SBOMs, and VEXs reporting.

* Open independence enabling digital sovereignty
Understanding the project’s relevance to teams, organizations and public bodies wanting independence from proprietary, closed data providers for supply chains metadata, is a growing concern for EU-based entities, and CodeSupply is an answer to this concern.

* Clear and multiple engagement modes
Leave knowing concretely how to engage with the CodeSupply project as a data consumer, data curator, code contributor, or sponsoring organization.