Software supply chain security
The complete secure-CI/CD picture. Start from the supply-chain threat landscape and the DevSecOps mindset, then secure each link: the source and its dependencies, the build (SLSA, hermetic and reproducible), signing and attestation (Sigstore, SBOMs, in-toto provenance), verification and policy enforcement at admission, and the operating practices — continuous rescanning, VEX, and incident response — that keep it working. Eighteen lessons across six sections, each ending with a self-test.
Progress is saved in this browser only — no account required.
Final exam
Test yourself on everything
54 questions drawn from all 6 sections — every answer explained as you pick.