Gartner defines software supply chain security (SSCS) tools as those that enable the building of secure software by protecting against compromises during development and delivery. These protections extend to source code, developer identities, development tools, delivery pipelines, and postdeployment patches. SSCS tools reduce third-party risks through policy-based curation of dependencies, software composition analysis (SCA) and software bill of materials (SBOM) inspection. They ensure artifact provenance and traceability with signing and verification as they pass through development and delivery pipelines. SSCS tools support SaaS and hybrid deployment models, and complement DevOps platforms in improving the organization’s DevSecOps maturity.