Skip to content
Software Supply Chain Security

Cybersecurity · DevOps

Software Supply Chain Security

By Owen Hart

4.6 ★ editorial rating

$32.00

  • Format EPUB, PDF
  • Pages 214
  • Published 2026-08-10
  • Language English
  • Skill Intermediate
  • Technology CI / npm / PyPI / Composer

Description

Lock down the path from git to production in 2026: lockfiles, provenance, signed builds, secrets in CI, and the npm/PyPI/Composer incidents that keep repeating.

What you’ll learn

  • Trust fewer packages by default
  • Prove what you shipped
  • Contain a compromised dependency

Table of contents

  1. The real attack surface
  2. Lockfiles and pinning
  3. Provenance and attestations
  4. CI identity
  5. What to do after a bad package

Author

Owen Hart

Application security without the fear-mongering.