<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/policy-as-code-in-the-software-supply-chain-evp6wnfqt" -->

---
title: Policy-as-Code in the software supply chain | daily.dev
description: Policy-as-Code is a modern approach that combines software engineering principles with operational and security guidelines to enhance compliance, consistency,...
canonical: https://daily.dev/posts/policy-as-code-in-the-software-supply-chain-evp6wnfqt
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Policy-as-Code in the software supply chain | daily.dev
og:description: Policy-as-Code is a modern approach that combines software engineering principles with operational and security guidelines to enhance compliance, consistency,...
og:url: https://daily.dev/posts/policy-as-code-in-the-software-supply-chain-evp6wnfqt
og:image: https://api.daily.dev/og/posts/EVP6wNfQT.png
og:image:alt: Policy-as-Code in the software supply chain
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Policy-as-Code in the software supply chain

**[CNCF](https://daily.dev/sources/cncf)** · 11 min read · 2 upvotes · 0 comments

## Summary

Policy-as-Code is a modern approach that combines software engineering principles with operational and security guidelines to enhance compliance, consistency, and efficiency in software supply chains. It focuses on creating, distributing, and evaluating policies for secure software supply chains. The implementation of policies spans various domains, including infrastructure, platform, source, build, and execution. Effective policy design and evaluation require accuracy, evaluation, and confidence. Trust establishment, policy distribution, and evaluation are crucial aspects of policy implementation. Policy-as-Code tools, such as gatekeepers and policy languages, can be used for policy implementation, enforcement, and evaluation.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.cncf.io/blog/2024/02/14/policy-as-code-in-the-software-supply-chain/>

---

Tags: [#compliance](https://daily.dev/tags/compliance), [#open-source](https://daily.dev/tags/open-source), [#policy-as-code](https://daily.dev/tags/policy-as-code), [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/policy-as-code-in-the-software-supply-chain-evp6wnfqt)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Policy-as-Code in the software supply chain","url":"https://daily.dev/posts/policy-as-code-in-the-software-supply-chain-evp6wnfqt","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/policy-as-code-in-the-software-supply-chain-evp6wnfqt"},"datePublished":"2024-02-14T16:05:18.980Z","dateModified":"2026-03-30T02:18:11.533Z","description":"Policy-as-Code is a modern approach that combines software engineering principles with operational and security guidelines to enhance compliance, consistency,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8b0d10374e374833de99933cbc41cdac?_a=AQAEufR","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8b0d10374e374833de99933cbc41cdac?_a=AQAEufR","isAccessibleForFree":true,"articleSection":"CNCF","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CNCF","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/55536a03390741eebd96d2f9b74d2d8d","url":"https://daily.dev/sources/cncf"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/policy-as-code-in-the-software-supply-chain-evp6wnfqt","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":2},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"compliance,open-source,policy-as-code,security","timeRequired":"PT11M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CNCF","item":"https://daily.dev/sources/cncf"},{"@type":"ListItem","position":3,"name":"Policy-as-Code in the software supply chain"}]}
```

