CodeSupply delivers correct, trusted, and verified software metadata, as an open source, federated, and digitally sovereign data catalog, necessary to manage and secure software supply chains. The decentralized distribution of open data democratizes access to valuable datasets, balancing the end-to-end traceability and discoverability of code with organizational autonomy and authority over data assets. Organizations struggle to manage and secure software supply chains with incorrect, inconsistent, or incomplete information about software. Critical metadata about origin and licenses, vulnerabilities, and project health is scattered across multiple databases, registries, and tools, often presenting conflicting or outdated information. Proprietary options lack transparency in their classification and decision-making processes, providing no reproducibility, traceability, or auditability - essential for organizational trust and regulatory requirements. This fragmentation creates compliance risks, security gaps, and operational inefficiencies that scale exponentially with the complexity of software supply chains. Open data about software packages is critical for the automation and scale necessary to resolve software supply chain security and compliance challenges. CodeSupply aggregates and curates comprehensive software metadata, leveraging Package-URLs (PURLs) as universal identifiers, including origin and licensing information, security vulnerabilities, and risk metrics from distributed, authoritative data sources across programming ecosystems and software types. This metadata is compiled into data sets, federated in a data catalog for digital sovereignty and independence, and distributed as open data, freely available to all. Utilizing NGI building blocks of free and open source tools, CodeSupply packages an effective and efficient solution for any software-producing or -consuming organization to manage, mitigate, and remediate any software supply chain challenges.
