Container Supply Chain Security: IT Teams Secure Software Chains
On average, the 70 most widely used Docker Hub container images contain 604 known vulnerabilities. Eighty-four percent of commercial codebases include at least one open-source vulnerability. And the EU Cyber Resilience Act …
On average, the 70 most-used Docker Hub container images harbour 604 known vulnerabilities each. Eighty-four percent of all commercial codebases contain at least one open-source vulnerability. And from 2027 the EU Cyber Resilience Act makes Software Bills of Materials mandatory. For IT teams in logistics, software supply-chain security is no longer optional–the SBOM mandate is drawing near.
Key Takeaways
- 604 vulnerabilities per image: The 70 most-used Docker Hub container images average 604 known vulnerabilities, over 40 percent of them critical or high (NetRise, December 2024).
- 75 percent affected: Three out of four organisations experienced a software-supply-chain attack within a year (BlackBerry, 2024).
- 704,102 malicious packages: Since 2019 more than 700,000 malicious packages have been identified in public repositories, up 156 percent year-over-year (Sonatype, 2024).
- SBOM mandate from 2027: The EU Cyber Resilience Act requires machine-readable Software Bills of Materials for all digital products. Fines: up to €15 million (EU CRA, 2024).
- NIS2 hits logistics directly: Transport, warehousing and freight are among the covered sectors. Reporting obligation: within 24 hours of discovering an incident.
Why the software supply chain is the new gateway
The attack surface has shifted. Instead of striking individual companies directly, attackers compromise software components used by thousands of firms at once. The XZ Utils incident in March 2024 (CVE-2024-3094, CVSS 10.0) showed the danger: a lone attacker infiltrated an open-source project for more than three years–mirroring the GlassWorm campaign in March 2026–and planted a backdoor enabling remote code execution over SSH. The attack was spotted only by chance when a Microsoft developer noticed an unusual delay (CISA Alert, March 2024).
For logistics the stakes are especially high. NotPetya proved in 2017 what happens when a compromised software update hits a supply chain: Maersk lost access to roughly 50,000 endpoints and 76 port terminals across 130 countries. The damage: about 261 million euros at Maersk alone, with global estimates reaching around 8.7 billion euros (CSO Online).
Source: NetRise Supply Chain Visibility Study, December 2024
What’s inside the containers
The NetRise study from December 2024 examined the 70 most-used Docker Hub container images and found an average of 604 known vulnerabilities per image. Over 40 percent are rated critical or high. Each image averages 389 software components, and one in eight components lacks any software manifest (Help Net Security, 2024).
More than 45 percent of the discovered vulnerabilities are between two and ten years old. That means long-patched flaws are repeatedly reintroduced into new deployments via outdated base images. Synopsys confirms the pattern: 91 percent of audited commercial codebases contain components at least ten versions out of date (OSSRA Report, 2024).
The Attack Vectors: Malicious Packages in Public Repositories
By August 2024, Sonatype had identified a total of 704,102 malicious packages in public repositories such as npm, PyPI, and Maven Central. Growth compared to the previous year: 156 percent. In 2024 alone, more than 400,000 new malicious packages were discovered. With 6.6 trillion expected open-source downloads by the end of 2024, the attack surface is expanding faster than defense capabilities (Sonatype, 10th State of the Software Supply Chain Report).
The consequence for logistics IT: every warehouse management system, every transport management system, and every IoT platform for fleet tracking relies on open-source components. If you don’t know the origin of these components, you have a blind spot in your own security architecture.
SBOM: The Bill of Materials for Software
A Software Bill of Materials lists every component of an application, including versions, licenses, and known vulnerabilities. What is taken for granted in physical supply chains (every logistics manager knows the contents of their containers) is often completely missing in the software supply chain.
The SBOM market is growing accordingly: from roughly 1.0 billion euros in 2024 to a projected 5.4 billion euros by 2033, at an annual growth rate of 21.5 percent (Anchore, 2025). Large enterprises account for 58 percent of users. Tools such as Trivy (open source, by Aqua Security), Snyk Container, and Sysdig automatically generate SBOMs as part of the CI/CD pipeline.
CRA and NIS2: Regulation is Coming
The EU Cyber Resilience Act (Regulation 2024/2847) has been in force since December 2024 and applies to all products with digital elements sold in the EU. From 11 September 2026, actively exploited vulnerabilities must be reported. From 11 December 2027, a machine-readable SBOM becomes mandatory. The format is not prescribed; SPDX and CycloneDX are accepted standards. Violations can cost up to 15 million euros or 2.5 percent of global annual turnover (EU Digital Strategy).
NIS2 hits logistics even more directly. Transport, warehousing, freight forwarding, and courier services are among the sectors covered. Companies with more than 50 employees or over 10 million euros in revenue fall under the directive. Requirements under Article 21 explicitly include assessing and securing all ICT suppliers and subcontractors. Incidents must be initially reported within 24 hours, assessed within 72 hours, and fully reported within one month. Personal liability of management in cases of negligence adds further pressure (nFlo, Dataguard).
Container Security in Practice
The container security market reached around 2.5 billion euros in 2024 and is projected to grow to 12.3 billion euros by 2032 (MarketsandMarkets). Tools are mature: Trivy scans container images, infrastructure-as-code files, and SBOMs in seconds. Sysdig uses eBPF for real-time detection directly inside Kubernetes clusters. Snyk Container integrates into the IDE and creates automatic fix pull requests.
For logistics IT teams, the practical recommendation is clear: regularly update base images (45 percent of known vulnerabilities are years old and avoidable), embed SBOM generation in the CI/CD pipeline, and enforce registry scanning before every deployment. If you are subject to NIS2, you must document these measures anyway.
Conclusion
The software supply chain is now the most critical attack surface for logistics companies: 604 vulnerabilities per container image, 704,000 malicious packages in public repositories, and a regulatory environment that demands transparency. SBOM, container scanning, and supply-chain security are no longer innovation projects. They are compliance mandates with deadlines–akin to the vendor-lock-in risks surrounding VMware.
Frequently Asked Questions
What is a Software Bill of Materials (SBOM)?
An SBOM is a machine-readable list of all software components in an application, including versions, licenses, and known vulnerabilities. It makes the composition of software transparent, much like an ingredients list on food packaging. The EU Cyber Resilience Act will mandate SBOMs for all digital products starting December 2027.
Does NIS2 also apply to mid-sized logistics companies?
Yes, if they employ more than 50 staff or generate over €10 million in annual revenue. Transport, warehousing, freight forwarding, and courier services are explicitly included in the covered sectors. Requirements include securing all ICT suppliers and reporting incidents within 24 hours.
What’s the difference between the CRA and NIS2 when it comes to software security?
The CRA governs the security of products with digital elements (software and hardware) and targets manufacturers. NIS2 governs the cybersecurity of organizations in critical sectors and targets operators. For logistics firms, this means: CRA applies to the software you use, while NIS2 applies to your organization itself. Both demand transparency across the software supply chain.
How do I find vulnerabilities in my container images?
Open-source tools like Trivy (Aqua Security) scan container images in seconds and deliver a detailed list of all vulnerabilities with CVSS scores. Commercial platforms such as Snyk, Sysdig, and Aqua Security also offer automated fixes, policy enforcement, and CI/CD pipeline integration.
How often should base images be updated?
At least monthly, and immediately when critical vulnerabilities are disclosed. Research by NetRise shows that over 45 percent of vulnerabilities in container images are between two and ten years old. Automated rebuild pipelines that regularly reconstruct base images largely eliminate this risk.
Further Reading
cloudmagazinNIS2 and SaaS Supply Chains: Compliance GapsMore from the MBF Media Network
SecurityTodayGlassWorm: 400+ Developer Tools CompromisedDigital ChiefsCSRD and Sustainability on the Board AgendaMyBusinessFutureCyber Resilience Act: Manufacturer ObligationsSource image: Pexels / Markus Spiske (px:2061168)

