About the village
Supply Chain Security Village
An open, community-run space for the people who find, exploit, and defend the software supply chain — talks, live demos, hands-on CTFs, and the researchers behind them.
The mission
Open Source. Community-Driven.
Supply Chain Security Village exists because supply chain security is one of the most critical — and most underserved — areas in cybersecurity today.
Most security training focuses on application vulnerabilities. But the real risk is upstream — in the dependencies developers pull without thinking, the build systems that run with implicit trust, and the CI/CD pipelines that deploy code with no verification of what changed along the way. These are the entry points attackers increasingly target, and there's no dedicated platform teaching practitioners how to defend against them.
The same pattern shows up well beyond code — in logistics and shipping, in procurement and third-party suppliers, in the hardware and firmware that arrive from three tiers down. Different vocabulary, same failure: trusting an upstream nobody verified. Our hands-on work is mostly on the software side, because that's where our experience is — but the people who move goods, parts, and components face this too, and they're welcome here.
We built this to fill that gap. No sponsors. No sales pitch. Just a community of security practitioners, developers, and researchers who believe that understanding supply chain threats requires hands-on practice — not slide decks.
Community-Driven
Every challenge, talk, and resource is created by practitioners. The platform grows because the community grows.
Open to All
All skill levels welcome. No gatekeeping, no paywalls. The supply chain is everyone's problem — and everyone's to defend.
Who this is for
Built for Practitioners
Developers & DevOps
Understand how the tools you use daily — package managers, CI systems, container registries — become attack vectors. Build with security in the pipeline, not as an afterthought.
Security Researchers
Sharpen your skills on real supply chain attack patterns. Dependency confusion, build poisoning, backdoor analysis — the new frontier of offensive security.
AppSec & Red Teams
Test and defend the supply chain. Learn to assess third-party risk, audit SBOMs, and find the gaps that traditional application pentests miss.
OSS Maintainers
Your project is someone else's dependency. Learn the patterns attackers use to compromise open-source packages and how to protect the software others rely on.
Students & Newcomers
No prior supply chain security experience needed. Start from the fundamentals and work your way up through real challenges — not textbooks.
Leadership
Leadership Team
We're growing — Looking for challenge designers, speakers, mentors, and volunteers. Whether you work on software, hardware, logistics, or the warehouse floor, if you care about how things get from source to destination safely, there's a place for you here.
Sponsors & Partners
Powered by community goodwill
Supply Chain Security Village runs on volunteer time and community support. We're looking for partners who share our mission.
Become a sponsor
Help us keep Supply Chain Security Village free and open. Sponsorships fund event infrastructure, prizes, and community grants.
Get involved
Ready to Find the Weak Link?
Speak. Design challenges. Mentor newcomers. Volunteer. Or just show up and hack. The supply chain needs more people paying attention.
Get Involved
