What you will learn
- Sign artifacts
- Generate SBOMs
- Pin and verify dependencies
New to this? Start here
The basics, in plain English
Attackers increasingly target the build pipeline itself, because whatever it builds gets trusted and shipped. Securing the supply chain means making sure every step and ingredient that goes into your software is trustworthy.
- Supply chain
- Everything that goes into your software: code, libraries, build steps, and tools.
- Dependency
- Outside code your app relies on. A poisoned dependency can compromise you.
- Signing
- Stamping an artifact with proof of who built it, so tampering is detectable.
- SBOM
- A “Software Bill of Materials”: a full list of everything inside your software.
- Provenance
- A trustworthy record of where an artifact came from and how it was built.
01
Supply chain
Sign builds, produce a software bill of materials, and verify what you ship. SLSA describes increasing levels of build integrity.
Finished this topic?
Mark it done to earn 100 XP and keep your streak alive.