All courses

Software supply chain security

The complete secure-CI/CD picture. Start from the supply-chain threat landscape and the DevSecOps mindset, then secure each link: the source and its dependencies, the build (SLSA, hermetic and reproducible), signing and attestation (Sigstore, SBOMs, in-toto provenance), verification and policy enforcement at admission, and the operating practices — continuous rescanning, VEX, and incident response — that keep it working. Eighteen lessons across six sections, each ending with a self-test.

Advanced6 sections · 18 lessons · ~9h total · 54-question self-test

Progress is saved in this browser only — no account required.

Final exam
Test yourself on everything
54 questions drawn from all 6 sections — every answer explained as you pick.
Start final exam