Supply Chain Security roadmap

Secure the build pipeline and dependencies: SBOMs, artifact signing, provenance, and SLSA. Build on secure SDLC and CI/CD, then add provenance, signing, and dependency risk management.

1 courses6 resourcesProduct security

Step-by-step path

  1. Dependencies, transitive risk, and generating SBOMs (Syft)
  2. Sign and verify artifacts with Sigstore (Cosign, Fulcio, Rekor)
  3. Apply SLSA provenance and harden CI/CD against tampering
  4. Build a portfolio artifact and publish a short writeup.