Secure the software and hardware supply chain — dependencies, build integrity, provenance, and vendor components. Use when hardening CI/CD, managing open-source risk, or responding to supply-chain attack threats.