Cybersecurity · DevOps
Software Supply Chain Security
$32.00
- Format EPUB, PDF
- Pages 214
- Published 2026-08-10
- Language English
- Skill Intermediate
- Technology CI / npm / PyPI / Composer
Description
Lock down the path from git to production in 2026: lockfiles, provenance, signed builds, secrets in CI, and the npm/PyPI/Composer incidents that keep repeating.
What you’ll learn
- Trust fewer packages by default
- Prove what you shipped
- Contain a compromised dependency
Table of contents
- The real attack surface
- Lockfiles and pinning
- Provenance and attestations
- CI identity
- What to do after a bad package