Software Supply Chain Security with Sigstore — LearnFlat
⏱ 2 h 36 min 📚 26 leçons 🎧 Version audio

Software Supply Chain Security with Sigstore

Learn how to protect your software distribution pipeline by signing and verifying artifacts using Cosign, Rekor, and Fulcio.

  • 💬 Instructeur IA
    Posez une question sur n'importe quelle leçon et obtenez une réponse claire à tout moment.
  • 🕐 Commencez quand vous voulez
    Sans horaires ni délais : apprenez à votre rythme, quand vous voulez.
  • 🌐 En français
    Leçons, exercices et certificat : tout entièrement dans votre langue.

À propos de ce cours

Software supply chain attacks are on the rise, making it critical to verify the integrity of every dependency and artifact you deploy. Understanding how to secure your code from commit to production is no longer optional—it is a core requirement for modern software delivery. This text-based course equips you with the fundamental skills to implement robust security practices using the open-source Sigstore ecosystem. You will learn how to sign, verify, and monitor software artifacts to ensure they remain untampered throughout the delivery pipeline. Through clear written explanations and configuration examples, you will master the principles of cryptographic verification. What you'll learn: - Understand the core concepts of software supply chain security and the SLSA framework. - Configure and use Cosign to sign and verify container images and digital artifacts. - Implement keyless signing using Fulcio and Rekor for seamless cryptographic verification. - Generate and integrate Software Bill of Materials (SBOMs) into your security workflow. - Verify the integrity of third-party dependencies before integration. - Establish transparency logs to monitor and audit digital signatures over time. You will start by exploring foundational security definitions and the mechanics of modern supply chain threats. From there, you will progress through structured written guides and real-world configuration examples to set up cryptographic signing and verification pipelines. This course is designed for software developers, DevOps beginners, and security enthusiasts who want to establish a solid foundation in supply chain security without needing prior cryptography experience. Start building a safer, more resilient software pipeline today.

Ce que vous recevez

  • 📜 Certificat de fin
    Ajoutez-le à votre profil LinkedIn
  • 💬 Tuteur AI personnel
    Bloqué sur une leçon ? Pose n'importe quelle question à ton tuteur intégré, à tout moment.
  • 🎧 Version audio incluse
    Apprenez en déplacement, sans écran
  • ♾️ Accès à vie
    Revenez quand vous voulez, sans expiration
  • 📱 Téléphone ou ordinateur
    Fonctionne partout, sur tout appareil
  • 💸 Remboursement 14 jours
    Sans poser de questions
  • Court et ciblé
    2 h 36 min de contenu pratique

Avis

Pas encore d'avis — soyez le premier à partager votre expérience.

Écrire un avis

Nous vous demanderons de vous connecter après envoi — votre brouillon est sauvegardé.

Autres apprenants ont aussi suivi

Questions fréquentes

De quoi ai-je besoin pour suivre ce cours ? +

Un téléphone ou un ordinateur avec internet, c'est tout. Aucune installation, aucun matériel spécial.

Comment payer ? +

Par carte via Stripe. Nous ne stockons pas les données de carte — Stripe les gère de manière sécurisée.

Puis-je obtenir un remboursement ? +

Oui — remboursement complet sous 14 jours, sans question.

Combien de temps aurai-je accès ? +

À vie. Une fois acheté, le cours est à vous, vous pouvez y revenir quand vous voulez.

Vais-je obtenir un certificat ? +

Oui. À la fin, vous recevez un certificat à ajouter à votre profil LinkedIn.

Conçu pour les apprenants en
Tech Design Finance Marketing Santé Éducation Hôtellerie Industrie