Free courses from frontend to fullstack and AI
Finance Certifications Goldman Sachs and Amazon Teams Trust
Overview
Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course examines software supply chain attack vectors involving dependencies, package managers, CI/CD pipelines, and build tools. It presents practices for inventory, software composition analysis, verification, provenance, and protection against compromised packages and pipeline misuse.
Syllabus
Introduction
Agenda
The Supply Chain
Devils Pipeline
Supply Chain Confusion
Package Squad
Namespaces
namespace confusion
Timelines
NPM Audit
NPM Autofix
MPQ Autofix
Attack Examples
SCVs
Gitbook
Inventory
Software Composition Analysis
Software Package Data Exchange
Verification Standard 3
Traceability
Package Management
Component Analysis
Provenance Pedigree
Taught by
NDC Conferences