CI/CDOptional

Pipeline Security & Supply Chain

Protect the path from source to production.

30 min read advanced 3 objectives

Status

Not started

What you will learn

  • Sign artifacts
  • Generate SBOMs
  • Pin and verify dependencies

New to this? Start here

The basics, in plain English

Attackers increasingly target the build pipeline itself, because whatever it builds gets trusted and shipped. Securing the supply chain means making sure every step and ingredient that goes into your software is trustworthy.

Supply chain
Everything that goes into your software: code, libraries, build steps, and tools.
Dependency
Outside code your app relies on. A poisoned dependency can compromise you.
Signing
Stamping an artifact with proof of who built it, so tampering is detectable.
SBOM
A “Software Bill of Materials”: a full list of everything inside your software.
Provenance
A trustworthy record of where an artifact came from and how it was built.
01

Supply chain

Sign builds, produce a software bill of materials, and verify what you ship. SLSA describes increasing levels of build integrity.

Finished this topic?

Mark it done to earn 100 XP and keep your streak alive.