Software Supply-Chain and Platform Security
Module Readiness: Learner-ready
The complete concept, adversarial practice, assessment, transfer, and source-routing path is available.
Selective Reading Rule
The guide is the primary teacher. Full-book reading is not required; use the module reading guide and linked standards or primary sources to resolve a named question.
Competency
Protect source, dependencies, builders, artifacts, deployment policy, and workload identity using SBOMs, signing, provenance, and SLSA.
Required Evidence
- SBOM
- signed artifact
- provenance verification
- policy-as-code denial evidence
Completion Gate
Reproduce the threat or failure, implement the control, verify it with negative evidence, and state the remaining risk. Scanner output without triage does not count.
Source Policy
Use current official standards and curated local book routes selectively. The completed guide must remain the primary teacher.