Lessons
1Bind CI identity to the exact deployment authority25 min read
Evaluate an OIDC trust policy for a build-to-cloud workflow.
- →Evaluate an OIDC trust policy for a build-to-cloud workflow
2Verify what an artifact attestation actually proves25 min read
Evaluate artifact identity and build provenance without overclaiming safety.
- →Evaluate artifact identity and build provenance without overclaiming safety
- →Separate artifact identity from claims about its safety
3Build a detection rule with a useful evidence trail25 min read
Define a security detection with measurable precision and response.
- →Define a security detection with measurable precision and response
- →Preserve detection evidence without exposing secrets
4Prioritize vulnerable dependencies from actual exposure25 min read
Choose a remediation order using version, reachability and impact evidence.
- →Choose a remediation order using version, reachability and impact evidence
Skills in this course
- 01Evaluate an OIDC trust policy for a build-to-cloud workflowEvaluate an OIDC trust policy for a build-to-cloud workflow.
- 02Evaluate artifact identity and build provenance without overclaiming safetyEvaluate artifact identity and build provenance without overclaiming safety.
- 03Define a security detection with measurable precision and responseDefine a security detection with measurable precision and response.
- 04Choose a remediation order using version, reachability and impact evidenceChoose a remediation order using version, reachability and impact evidence.
- 05Separate artifact identity from claims about its safetySeparate artifact identity from claims about its safety.
- 06Preserve detection evidence without exposing secretsPreserve detection evidence without exposing secrets.