Skip to main content

Software Supply-Chain and Platform Security

Module Readiness: Learner-ready

The complete concept, adversarial practice, assessment, transfer, and source-routing path is available.

Selective Reading Rule

The guide is the primary teacher. Full-book reading is not required; use the module reading guide and linked standards or primary sources to resolve a named question.

Competency

Protect source, dependencies, builders, artifacts, deployment policy, and workload identity using SBOMs, signing, provenance, and SLSA.

Required Evidence

  • SBOM
  • signed artifact
  • provenance verification
  • policy-as-code denial evidence

Completion Gate

Reproduce the threat or failure, implement the control, verify it with negative evidence, and state the remaining risk. Scanner output without triage does not count.

Source Policy

Use current official standards and curated local book routes selectively. The completed guide must remain the primary teacher.