Skip to main content

CI Adversary and Release Lab

Attack an untrusted pull-request workflow, minimize identities and secrets, separate approval, and prove the same verified digest reaches each environment.

Required evidence

Submit threat paths, machine-readable inventory and provenance, verified identities and digests, policy decisions, negative tampering test, exception lifecycle, recovery evidence, and residual risk. A badge or scanner report without verification does not pass.

Oral defense

Trace running bytes to reviewed source, demonstrate a failed tampering attempt, explain the verifier trust root, and execute revocation plus clean rebuild.

Source backbone

Use SLSA, NIST SSDF, Sigstore, Kubernetes admission documentation, and Building Secure and Reliable Systems.