Professional Course

Securing Your Software Supply Chain with Sigstore

edX, Online
Length
7 weeks
Price
149 USD
Next course start
Start anytime See details
Delivery
Self-paced Online
Length
7 weeks
Price
149 USD
Next course start
Start anytime See details
Delivery
Self-paced Online
Visit this course's homepage on the provider's site to learn more or book!

Course description

Securing Your Software Supply Chain with Sigstore

Building and distributing software that is secure throughout its entire lifecycle can be challenging, leaving many projects unprepared to build securely by default. Attacks and vulnerabilities can emerge at any step of the chain, from writing to packaging and distributing software to end users. Sigstore is one of several innovative technologies that have emerged to improve the integrity of the software supply chain, reducing the friction developers face in implementing security within their daily work.

This course is designed with end users of Sigstore tooling in mind: software developers, DevOps engineers, security engineers, software maintainers, and related roles. To make the best of this course, you will need to be familiar with Linux terminals and using command line tools. You will also need to have intermediate knowledge of cloud computing and DevOps concepts, such as using and building containers and CI/CD systems like GitHub actions.

This course will introduce you to Cosign, Fulcio, and Rekor, the tools under the Sigstore umbrella, explaining how they support a more secure software supply chain. You will learn how to employ these tools throughout your software development, testing, and distribution processes. Additionally, those who use or implement your software will be able to verify its authenticity through tamper-resistant public logs.

Upon completing this course, you will be able to inform your organization’s security strategy and build software more securely by default.

Upcoming start dates

1 start date available

Start anytime

  • Self-paced Online
  • Online
  • English

Who should attend?

Prerequisites

  • Familiarity with using the command line
  • Intermediate knowlegde of cloud computing and DevOps concepts, such as containers, CI/CD systems, GitHub actions, etc.
  • Familiarity with using and building container images

Training content

  • Introducing Sigstore
  • Cosign: Container Signing, Verification, and Storage in an OCI Registry
  • Fulcio: A New Kind of Root Certificate Authority For Code Signing
  • Rekor: Software Supply Chain Transparency Log
  • Sigstore: Using the Tools and Getting Involved with the Community
  • Final Exam

Course delivery details

This course is offered through The Linux Foundation, a partner institute of EdX.

1-2 hours per week

Costs

  • Verified Track -$149
  • Audit Track - Free

Certification / Credits

What you'll learn

  • Describe the components of Sigstore and how they support a more secure software supply chain.
  • Sign and verify software artifacts with Sigstore.
  • Understand how to implement Sigstore within the software development lifecycle.

Contact this provider

Contact course provider

Fill out your details to find out more about Securing Your Software Supply Chain with Sigstore.

  Contact the provider

  Get more information

  Register your interest

Country *

reCAPTCHA logo This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
edX
141 Portland Street
02139 Cambridge Massachusetts

edX

edX For Business helps leading companies upskill their labor forces by making the world’s greatest educational resources available to learners across a wide variety of in-demand fields. edX For Business delivers high-quality corporate eLearning to train and engage your employees...

Read more and show all training delivered by this supplier

Ads