Ir al contenido principal

LinuxFoundationX: Securing Your Software Supply Chain with Sigstore

Gain the knowledge and skills necessary to secure the integrity of your software by leveraging the Sigstore toolkit, a free and open source project that offers automated signing and verification across release files, container images, binaries, bill of material manifests, and more.

Securing Your Software Supply Chain with Sigstore
7 semanas
1–2 horas por semana
A tu ritmo
Avanza a tu ritmo
Gratis
Verificación opcional disponible

Hay una sesión disponible:

Una vez finalizada la sesión del curso, será archivadoAbre en una pestaña nueva.
Comienza el 26 abr

Sobre este curso

Omitir Sobre este curso

Building and distributing software that is secure throughout its entire lifecycle can be challenging, leaving many projects unprepared to build securely by default. Attacks and vulnerabilities can emerge at any step of the chain, from writing to packaging and distributing software to end users. Sigstore is one of several innovative technologies that have emerged to improve the integrity of the software supply chain, reducing the friction developers face in implementing security within their daily work.

This course is designed with end users of Sigstore tooling in mind: software developers, DevOps engineers, security engineers, software maintainers, and related roles. To make the best of this course, you will need to be familiar with Linux terminals and using command line tools. You will also need to have intermediate knowledge of cloud computing and DevOps concepts, such as using and building containers and CI/CD systems like GitHub actions.

This course will introduce you to Cosign, Fulcio, Rekor, and the Policy Controller, the tools under the Sigstore umbrella, explaining how they support a more secure software supply chain. You will learn how to employ these tools throughout your software development, testing, and distribution processes. Additionally, those who use or implement your software will be able to verify its authenticity through tamper-resistant public logs.

Upon completing this course, you will be able to inform your organization’s security strategy and build software more securely by default.

De un vistazo

  • Institution LinuxFoundationX
  • Subject Informática
  • Level Introductory
  • Prerequisites
    • Familiarity with using the command line
    • Intermediate knowlegde of cloud computing and DevOps concepts, such as containers, CI/CD systems, GitHub actions, etc.
    • Familiarity with using and building container images
  • Language English
  • Video Transcript English
  • Associated skillsLinux, Github, Vulnerability, DevOps, Tooling, Packaging And Labeling, Open Source Technology, Command-Line Interface, Supply Chain, Security Strategies, Innovation, Software Development, Manifests, Cloud Computing, Automation, Bill Of Materials

Lo que aprenderás

Omitir Lo que aprenderás
  • Describe the components of Sigstore and how they support a more secure software supply chain.

  • Sign and verify software artifacts with Sigstore.

  • Understand how to implement Sigstore within the software development lifecycle.

Plan de estudios

Omitir Plan de estudios
  • Welcome
  • 1. Introducing Sigstore
  • 2. Cosign: Signing and Verifying Containers and Artifacts
  • 3. Fulcio: The Trusted Digital Certificate Authority
  • 4. Rekor: The Immutable and Secure Transparency Log
  • 5. Policy Controller: The Kubernetes Cluster Gatekeeper
  • 6. Getting Involved with the Sigstore Community
  • Final Exam (verified track only)

¿Quién puede hacer este curso?

Lamentablemente, las personas residentes en uno o más de los siguientes países o regiones no podrán registrarse para este curso: Irán, Cuba y la región de Crimea en Ucrania. Si bien edX consiguió licencias de la Oficina de Control de Activos Extranjeros de los EE. UU. (U.S. Office of Foreign Assets Control, OFAC) para ofrecer nuestros cursos a personas en estos países y regiones, las licencias que hemos recibido no son lo suficientemente amplias como para permitirnos dictar este curso en todas las ubicaciones. edX lamenta profundamente que las sanciones estadounidenses impidan que ofrezcamos todos nuestros cursos a cualquier persona, sin importar dónde viva.

¿Te interesa este curso para tu negocio o equipo?

Capacita a tus empleados en los temas más solicitados con edX para Negocios.