On the way
Supply-Chain Security: SBOMs, Signing, and Provenance
After SolarWinds and Log4j, software supply-chain security is non-negotiable. A practical intro to SBOMs, artifact signing with Sigstore, and SLSA provenance in your pipeline.
I will break this one down in full soon. Dropping 2026-10-15, come back then and we will dive into the whole story.
#devsecops#security#supply-chain#ci-cd#containers