> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/tools-as-an-asset.md).

# Tools as an asset

The **Software supply chain tool inventory** provides comprehensive visibility into the tools, services, and third-party integrations that operate across your software development and delivery processes. It includes two complementary inventories:

* [Supply Chain Tools](#UUID-a3d48fe9-2877-8d2a-170c-c98fe167f3e9): Lists tools and their associated risk factors detected in your environment
* [Supply Chain Catalog](#UUID-fad734d0-b3c4-06ef-6ebf-b2dd19f1644d): Cortex Cloud's centralized registry of recognized supply-chain tools and their associated risk factors

Together, these inventories allow you to assess tool usage, coverage, and security posture—identifying unused, vulnerable, or unapproved tools before they expand your attack surface.

## Execution environments

Cortex Cloud supports these Supply Chain Tool execution environments:

* **Third party pipelines**: Third-party plugins integrated with Cortex Cloud, provide visibility into installations, locations, and CVE vulnerabilities within your pipeline environment. This allows for prioritized remediation, effectively reducing your attack surface by identifying and removing unused or vulnerable plugins.

  Supported pipeline environments include:

  * **GitHub Actions**
  * **Jenkins plugins**
  * **CircleCI Orbs**
  * **Azure Extensions**

  Additionally, these pipelines often incorporate third-party executables into their workflows. Cortex Cloud offers enhanced visibility into these third-party services, transforming unreadable data into actionable insights for improved security posture.
* **VCS third parties**: **VCS Apps**. Third-party applications and webhooks in your version control system. This enables removal of unused assets, management of permissions, and adherence to the principle of least privilege
* **Executables**: Standalone programs or scripts executed within your CI/CD pipelines. These may include custom scripts, third-party command-line tools, or other executable files. The inventory provides insights into their usage, deployment locations, and potential security risks
* **Remote Scripts (URL)**. Executable scripts fetched from a remote URL during pipeline execution. The inventory provides insights into their origin, usage, and potential security risks, addressing the unique challenges of untrusted remote code
* **Webhooks**: Automated, event-driven communications that trigger actions across your CI/CD pipeline and integrated services. Cortex Cloud provides an inventory of these webhooks, enabling you to assess their usage, coverage, and potential security risks

## Tool status

Tools are categorized by status: **Approved**, **Pending Review**, or **Rejected** (but still in use). When initially detected, tools are assigned a **Pending Review** status by default, requiring further action to change the status to **Approved** or **Rejected**. **Rejected** does not mean the tool is not in use. It allows application security practitioners and DevOpsSec personnel to search for and remove these tools as needed.

You can modify the tool status by right-clicking on a tool in both Supply Chain Tool and Supply Chain Catalog inventories:

* In the inventory table, **right-click on a tool** → **Change Status** → **select a status**
* From the **Overview** tab on the Supply Chain side-panel.
  * Initial selection: Select a status from the available options
  * When modifying a previous selection: Select **Edit** → **select a status**

For information about changing a tool status, refer to [Overview](#UUID-1f6447d5-765b-b3b6-a766-e24bf6ddd5ce_section-idm23482364300859)

## Understand the inventories

* Use **Supply Chain Tools** to view and manage tools detected in your environment, review usage, and prioritize remediation
* Use the **Supply Chain Catalog** to cross-reference detected tools against Cortex Cloud-supported ones, identify coverage gaps, and evaluate risk before integrating new tools or replacing existing ones

{% hint style="info" %}

### Note

Although attributes are identical across inventories, their values for the same tool can differ, most commonly in **Risk Factors** and **Type**. This is because the inventory reflects your live environment, which may include different versions or configurations than the catalog—for example, a package may not have been upgraded or may be deployed differently.
{% endhint %}

### Active tools

The **Active tools** (Customer's environment) provides detailed information about individual tools, including deployments, areas of non-use, and functionality detected in your SDLC. This data allows you to assess tool usage, coverage, and potential security risks.

#### Use cases

* **Tool visibility:** Gain visibility into all tools used across CI/CD pipelines and VCSs
* **Third-Party tools:** Discover and monitor all external tools (webhooks, executables, apps, plugins) integrated into your CI/CD pipelines and VCSs
* **Detailed Tool insights:** Access detailed information on each tool (creator, risk factors such as deprecation or low usage, usage evidence, first seen date, category) to evaluate approval status and assess risk
* **Rejected Tool Monitoring:** Manage tool approval status by approving or rejecting tools found in pipelines/VCSs, identifying non-compliant usage
* **Usage:** View tool usage indicators by category across pipelines/VCSs for management reporting internal as well as external usage

### Supply Chain Tools

The **Supply Chain Tools** inventory table provides a detailed list of your organization's CI/CD pipeline tools and VCS Apps, allowing you to view and manage your organization's supply chain tools from a single, centralized location. You can review tool usage, third-party integrations, and risk assessments, including creator information, usage evidence, and category details. Additionally, you can filter tools by status (approved, rejected, uncategorized) and category, search for specific tools, and identify top risks to ensure policy adherence and prioritize remediation.

### How to access Supply Chain Tools

To access Supply Chain Tools, select **Modules** → **Application Security** → **Supply Chain Tools (under 3rd Party Tools).**

### Supply Chain Tools inventory

The inventory table describes the exposed Supply Chain tool properties. You can view additional properties through the **Table Settings Menu**.

| Property/ Attribute | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| ------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Name                | The name of the Supply Chain tool                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Risk Factors        | <p>Risk factors associated with the tool, as assessed by Cortex Cloud, help you identify and prioritize potential risks for tools and components based on their likely impact and exploitability. Values include Archived, Not verified, Unsecured URL and Outdated Version.</p><p>For tools in your environment, risk factors are specific to the exact version you have, whereas catalog risk factors reflect the tool’s general profile. To understand the specific reasoning behind a risk factor, hover over it to view a detailed explanation</p> |
| Status              | The tool status. Values: Approved, Pending, Rejected                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| Usage               | The amount of CI/CD pipelines in which the tool was used. Includes a link which opens the location in which the tool is used                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Type                | The type of tool                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Category            | The category associated with the tool, such as Version Control System (VCS), Continuous Integration (CI) Servers and Build Automation Tools                                                                                                                                                                                                                                                                                                                                                                                                             |

### Expanded Supply Chain tool information

When you click a tool's entry in the inventory table, a side card will open to display detailed information. The information is organized into three tabs: the **Overview** tab, which provides a summary of the tool's key details and is the default view; the **Vulnerabilities** tab, which lists any associated security vulnerabilities (CVEs); and the **Actions** tab, which outlines available mitigation options for the tool.

{% tabs %}
{% tab title="Overview" %}
The **Overview** tab includes these details:

* **Name**: The name of the tool
* **Description**: A description of the tool usage and a link to its third-party origin, such as a public repository, documentation portal, or the vendor's official website
* **PAN insights**: Cortex Cloud mitigation recommendations based on risk factors to address relevant supply-chain threats
* **Timestamp**: When the tool was initially detected
* **Category**: The tool type, such as code scanning and analytics
* **Usage**: The amount of assets using this tool
* **Status**: The current status of the tool. Values include **Approved**, **Pending Review**, **Rejected**. You can manually override the system-assigned status
* **Approve** / **Reject**: Approve or reject the tool.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p><strong>AppSec Admin</strong> user permissions are required to perform these actions.</p></div>
* **Execution environments**: A list of execution environments associated with the tool. Details include: name, the number of assets using the tool and the scan type
  {% endtab %}

{% tab title="Usage" %}
The **Usage** tab provides a list of the execution environments associated with the tool. Details include

* The asset name in which the tool runs (such as a pipeline). Selecting the name opens the asset in a side-car without having to navigate to the dedicated **Assets** page
* The type of asset, such as CI/CD pipeline, CI/CD instance, or Organization (for VCS Apps)
* Evidence of the tool in the environment - the location of the file containing the tool
* When the tool was initially detected.
  {% endtab %}
  {% endtabs %}

#### Vulnerabilities

The **Vulnerabilities** tab is displayed whenever one or more tools has a risk factor that is a result of a Common Vulnerability and Exposure (CVE). This tab provides a consolidated list of all CVEs impacting the tools. The table includes these properties:

* **Name**. The unique identifier for the CVE entry. For example, CVE-2023-25764. This name is a clickable link that directs you to a detailed report on the vulnerability from a public database
* **CVSS Score**. The numerical score assigned to the vulnerability based on the Common Vulnerability Scoring System (CVSS). This score indicates the severity of the vulnerability, with a higher number representing a greater risk
* **Asset**: The specific asset affected by the CVE

#### Comments

Select the **Comments** icon in the side-panel to add comments directly to catalog items, enabling collaboration and internal notes between security and development teams regarding component usage, justification, or deprecation status.

## Supply chain catalog

The **Supply Chain Catalog (Platform knowledge base)** is Cortex Cloud's centralized registry of Cortex Cloud supported supply-chain tools and their associated risk factors. The catalog is distinct from the inventory displayed on the **Supply Chain Tools** page, which lists tools detected in your environment. Some tools may be displayed in both inventories - for example if you use Semgrep, which is also included in the catalog.

#### Use case

Use the catalog to cross-reference against your inventory to identify coverage gaps, assess exposure, and benchmark your security posture before integrating new tools or to replace existing ones that may be at risk.

### How to access the Supply Chain Catalog

To access the Supply Chain Catalog, select **Modules** → **Application Security** → **Supply Chain Catalog (under 3rd party tools)**.

### Supply Chain Catalog inventory

This inventory includes a list of all supply chain tools in the Catalog. The inventory table properties are identical to the Supply Chain Tools inventory table. For information about these properties, refer to [Supply Chain Tools](#UUID-a3d48fe9-2877-8d2a-170c-c98fe167f3e9).

#### Expanded Supply Chain catalog information

When you click a tool's entry in the inventory table, a side card opens to display detailed information. The information is organized into three tabs:

* **Overview**: Provides a summary of the tool's key details and is the default view
* **Vulnerabilities** Lists any associated security vulnerabilities (CVEs)
* **Actions**: Outlines available mitigation options for the tool

The details provided in these tabs are identical to the details displayed in the expanded Supply Chain Tool Catalog. For information about these properties, refer to [Expanded Supply Chain tool information](#UUID-1f6447d5-765b-b3b6-a766-e24bf6ddd5ce).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/application-security/software-supply-chain-security/visibililty-and-inventory/supply-chain-assets/tools-as-an-asset.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
