Fakta
"SLSA Provenance: Building Verifiable Builds and Release Pipelines"
Modern supply-chain attacks rarely break cryptography—they exploit ambiguity: which source was built, which dependencies were actually used, and whether a CI system can be trusted to tell the truth. This book is written for experienced engineers, security architects, and platform teams who need verifiable answers, not best-effort metadata. It takes a threat-model-first approach to provenance, showing how to reason about trust boundaries, attacker capabilities, and what “integrity” really means in real CI/CD environments.
You’ll learn SLSA v1.2 as an engineering discipline: how tracks and levels translate into concrete controls and measurable guarantees, and how to produce provenance that stands up to adversarial scrutiny. The book goes deep on the in-toto/DSSE attestation model, artifact identity by digest, and the SLSA Provenance predicate v1—especially builder identity, buildType design, and dependency capture for (near-)hermetic builds. It then moves to operational reality: hardening builders, choosing between keyed and keyless signing (Sigstore), distributing attestations at scale, and building policy-based verification that can gate releases.
Examples are oriented around practical flows (e.g., cosign-based production and verification), with special attention to failure modes, incident response, and progressive enforcement strategies that improve security without stopping delivery. Familiarity with CI/CD systems, container registries, and modern signing/identity concepts is assumed.
© 2026 NobleTrex Press (E-bog): 6610001191580
Udgivelsesdato
E-bog: 23. marts 2026
Over 1 million titler
Download og nyd titler offline
Eksklusive titler + Mofibo Originals
Børnevenligt miljø (Kids Mode)
Det er nemt at opsige når som helst
For dig som lytter og læser ofte.
129 kr. /måned
Eksklusivt indhold hver uge
Fri lytning til podcasts
Ingen binding
For dig som lytter og læser ubegrænset.
159 kr. /måned
Eksklusivt indhold hver uge
Fri lytning til podcasts
Ingen binding
For dig som ønsker at dele historier med familien.
Fra 179 kr. /måned
Fri lytning til podcasts
Kun 39 kr. pr. ekstra konto
Ingen binding
179 kr. /måned
For dig som vil prøve Mofibo.
89 kr. /måned
Gem op til 100 ubrugte timer
Eksklusivt indhold hver uge
Fri lytning til podcasts
Ingen binding
Har du en rabatkode?
Indtast koden her