When to activate: supply chain security, SBOM, dependency pinning, Sigstore, Cosign, provenance attestation, SLSA framework, software bill of materials