Lessons

1Bind CI identity to the exact deployment authority25 min read

Evaluate an OIDC trust policy for a build-to-cloud workflow.

  • →Evaluate an OIDC trust policy for a build-to-cloud workflow
Read lesson
2Verify what an artifact attestation actually proves25 min read

Evaluate artifact identity and build provenance without overclaiming safety.

  • →Evaluate artifact identity and build provenance without overclaiming safety
  • →Separate artifact identity from claims about its safety
Read lesson
3Build a detection rule with a useful evidence trail25 min read

Define a security detection with measurable precision and response.

  • →Define a security detection with measurable precision and response
  • →Preserve detection evidence without exposing secrets
Read lesson
4Prioritize vulnerable dependencies from actual exposure25 min read

Choose a remediation order using version, reachability and impact evidence.

  • →Choose a remediation order using version, reachability and impact evidence
Read lesson

Skills in this course

  1. 01Evaluate an OIDC trust policy for a build-to-cloud workflowEvaluate an OIDC trust policy for a build-to-cloud workflow.
  2. 02Evaluate artifact identity and build provenance without overclaiming safetyEvaluate artifact identity and build provenance without overclaiming safety.
  3. 03Define a security detection with measurable precision and responseDefine a security detection with measurable precision and response.
  4. 04Choose a remediation order using version, reachability and impact evidenceChoose a remediation order using version, reachability and impact evidence.
  5. 05Separate artifact identity from claims about its safetySeparate artifact identity from claims about its safety.
  6. 06Preserve detection evidence without exposing secretsPreserve detection evidence without exposing secrets.