All courses

Software supply chain in depth

End-to-end, verifiable trust from commit to running workload: the supply-chain threat model and SLSA levels, in-toto attestations and build provenance, Sigstore internals (cosign, Fulcio keyless, Rekor transparency log), SBOMs with Syft/Grype and VEX, dependency integrity, and enforcing it all at admission — plus hardening the CI/CD pipeline itself. Builds on the intermediate supply-chain course.

Advanced5 sections · 15 lessons · ~9h total · 60-question self-test

Progress is saved in this browser only — no account required.

Final exam
Test yourself on everything
60 questions drawn from all 5 sections — every answer explained as you pick.
Start final exam