Beginner

Container Supply Chain Security Essentials

Step into the Spotlight with AppSec Expertise: Use coupon ‘SKILLUP30’ and get 30% Off on Individual Pro Annual Plans.
Learning Path
Container Security
Ideal for
Developer
DevOps
Security Engineer
5
Hours
9
Lessons
6
Cloud Labs

Supply chains are a key part of managing software projects at scale. This course will take a hands-on focus on tools, workloads, and methods to manage even the most complex Container supply chains.

We'll start by learning about the problems with container supply chains, and establishing trust in the supply chains. Next, we'll use hands-on labs to generate and manage Container Software Bill of Materials (SBOM). To do this, we'll use tools like Syft to generate the SBOM, and Grype to scan the SBOM for vulnerabilities.

We'll also trojanizing container problems, container image provenance, and explore Project Sigstore. Here, you'll learn how to use Cosign, Rekor, and Fulcio to maintain a secure software supply chain at every step of the process.

You might also like these courses

Or explore these Learning Paths

Labs

ImageTragick

Syft and grype

Cosign

Cosign with Blob

Kyeless signing

Keyless signing github actions

Ready to Elevate Your Security Training?

Empower your teams with the skills they need to secure your applications and stay ahead of the curve.
Get Our Newsletter
Get Started
X
X
Copyright AppSecEngineer © 2023