There are several good references in https://github.com/chughes757/SecureSoftwareSupplyChain and most importantly a simple categorization.