01 - Introduction
The software supply chain encompasses everything that touches your software before it reaches production: source code, dependencies, build tools, CI/C...
Supply Chain Security & SLSA
Welcome to the Software Supply Chain Security guide. In an era where attackers target the build pipelines, dependencies, and deployment mechanisms rather than the application itself, securing the software supply chain is paramount.
01. Understanding SLSA v1.0 Foundation
1. The Concept (ELI5)
02 - SBOM Generation and Vulnerability Management
You can automatically generate an SBOM for your project, container, or filesystem using open-source tools like **Syft**.
02. Dependency Confusion
1. The Concept (ELI5)
03 - Dependency Pinning and Provenance
A critical practice in securing your software supply chain is ensuring that builds are reproducible. If `npm install` installs different sub-dependenc...
03. Typosquatting & Malicious Packages
1. The Concept (ELI5)
04 - Open Source Malware and Typosquatting
Attackers often attempt to compromise developer machines or CI servers by publishing malicious packages.
04. Build Integrity & Provenance
1. The Concept (ELI5)
05 - Secure Software Publishing
Once your software is built securely, you must ensure it remains secure when delivered to your users.
05. Artifact Signing with Sigstore
1. The Concept (ELI5)
06 - Hands-on Lab
1. Analyze a simulated malicious npm package that uses install scripts.
06. Securing CI/CD Pipelines
1. The Concept (ELI5)
07 - References
Comprehensive security guide and practical technical implementation handbook.
07. SBOM Generation & Validation
1. The Concept (ELI5)