Lyt når som helst, hvor som helst

Dyk ned i over 1 million e- og lydbøger samt podcasts.

  • Over 1 million titler
  • Eksklusive titler + Mofibo Originals
  • Download og nyd titler offline
  • Opsig når som helst
Prøv nu
DK - Details page - Device banner - 894x1036
Cover for SLSA Provenance: Building Verifiable Builds and Release Pipelines

SLSA Provenance: Building Verifiable Builds and Release Pipelines

Sprog
Engelsk
Format
Kategori

Fakta

"SLSA Provenance: Building Verifiable Builds and Release Pipelines"

Modern supply-chain attacks rarely break cryptography—they exploit ambiguity: which source was built, which dependencies were actually used, and whether a CI system can be trusted to tell the truth. This book is written for experienced engineers, security architects, and platform teams who need verifiable answers, not best-effort metadata. It takes a threat-model-first approach to provenance, showing how to reason about trust boundaries, attacker capabilities, and what “integrity” really means in real CI/CD environments.

You’ll learn SLSA v1.2 as an engineering discipline: how tracks and levels translate into concrete controls and measurable guarantees, and how to produce provenance that stands up to adversarial scrutiny. The book goes deep on the in-toto/DSSE attestation model, artifact identity by digest, and the SLSA Provenance predicate v1—especially builder identity, buildType design, and dependency capture for (near-)hermetic builds. It then moves to operational reality: hardening builders, choosing between keyed and keyless signing (Sigstore), distributing attestations at scale, and building policy-based verification that can gate releases.

Examples are oriented around practical flows (e.g., cosign-based production and verification), with special attention to failure modes, incident response, and progressive enforcement strategies that improve security without stopping delivery. Familiarity with CI/CD systems, container registries, and modern signing/identity concepts is assumed.

© 2026 NobleTrex Press (E-bog): 6610001191580

Udgivelsesdato

E-bog: 23. marts 2026

Tags

    Vælg dit abonnement

    • Over 1 million titler

    • Download og nyd titler offline

    • Eksklusive titler + Mofibo Originals

    • Børnevenligt miljø (Kids Mode)

    • Det er nemt at opsige når som helst

    Den mest populære

    Premium

    For dig som lytter og læser ofte.

    129 kr. /måned

    • Eksklusivt indhold hver uge

    • Fri lytning til podcasts

    • Ingen binding

    Prøv gratis

    Unlimited

    For dig som lytter og læser ubegrænset.

    159 kr. /måned

    • Eksklusivt indhold hver uge

    • Fri lytning til podcasts

    • Ingen binding

    Start tilbuddet

    Family

    For dig som ønsker at dele historier med familien.

    Fra 179 kr. /måned

    • Fri lytning til podcasts

    • Kun 39 kr. pr. ekstra konto

    • Ingen binding

    Dig + 1 familiemedlem2 konti

    179 kr. /måned

    Prøv gratis

    Flex

    For dig som vil prøve Mofibo.

    89 kr. /måned

    • Gem op til 100 ubrugte timer

    • Eksklusivt indhold hver uge

    • Fri lytning til podcasts

    • Ingen binding

    Prøv gratis