Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Protect Yourself Against Supply Chain Attacks

NDC Conferences via YouTube

Overview

This course aims to help learners understand and protect against supply chain attacks in their pipelines. The course covers various attack vectors such as breaking out of shell scripts, misusing third-party packages, and squatting internal package names. By the end of the course, learners will be able to identify potential vulnerabilities in their pipelines and implement strategies to mitigate supply chain attacks. The course teaches skills such as package management, software composition analysis, and verification standards. The teaching method includes theoretical explanations, real-world examples, and practical demonstrations. This course is intended for software developers, DevOps engineers, cybersecurity professionals, and anyone involved in software development and deployment processes.

Syllabus

Introduction
Agenda
The Supply Chain
Devils Pipeline
Supply Chain Confusion
Package Squad
Namespaces
namespace confusion
Timelines
NPM Audit
NPM Autofix
MPQ Autofix
Attack Examples
SCVs
Gitbook
Inventory
Software Composition Analysis
Software Package Data Exchange
Verification Standard 3
Traceability
Package Management
Component Analysis
Provenance Pedigree

Taught by

NDC Conferences

Reviews

Start your review of Protect Yourself Against Supply Chain Attacks

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.