Software supply chain in depth
End-to-end, verifiable trust from commit to running workload: the supply-chain threat model and SLSA levels, in-toto attestations and build provenance, Sigstore internals (cosign, Fulcio keyless, Rekor transparency log), SBOMs with Syft/Grype and VEX, dependency integrity, and enforcing it all at admission — plus hardening the CI/CD pipeline itself. Builds on the intermediate supply-chain course.
Progress is saved in this browser only — no account required.
Final exam
Test yourself on everything
60 questions drawn from all 5 sections — every answer explained as you pick.