Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Finance Certifications Goldman Sachs and Amazon Teams Trust
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
Learn about AMPEL, an open source policy engine designed to address supply chain security challenges in software development. Discover how this multi-purpose tool serves as the missing piece in the supply chain ecosystem by natively understanding in-toto attestations, verifying keyless Sigstore signatures, and comprehending any attestation predicate type. Explore AMPEL's embeddable capabilities that enable it to examine SBOMs and warn about problematic dependencies, interpret security scans to gate builds when vulnerabilities are detected, and prevent artifact publishing when security frameworks aren't met. Understand how AMPEL is building an ecosystem of tools, starting with the bnd attester, that can work across the Software Development Life Cycle (SLDC) to secure CI/CD systems. Examine practical examples demonstrating how AMPEL ensures compliance in hardened pipelines through verifiable evidence, making the wealth of security metadata generated by the supply chain security community finally actionable and useful for developers and organizations seeking to build trustworthy software.
Syllabus
Builds You (and Others) Can Trust: Meet the AMPEL Policy Engine - Adolfo GarcÃa Veytia
Taught by
Linux Foundation