A tailored course, built for your situation
Mastering SLSA for Senior Software Supply Chain Practitioners
Build verifiable, production-grade software supply chain integrity with confidence and precision
The situation this course is for
Without a structured approach to SLSA implementation, even strong teams default to compliance-by-checklist, missing the strategic leverage of being the first call on vendor integrations and new build validations.
Who this is for
Senior software engineers, platform leads, and security architects who operate at the intersection of code integrity, CI/CD governance, and vendor trust frameworks
Who this is not for
Entry-level developers, auditors focused only on checklist compliance, or teams without ownership of build pipeline decisions
What you walk away with
- Design SLSA Level 3+ compliant build systems from first principles
- Produce signed, machine-verifiable attestations for any build pipeline
- Lead vendor onboarding using SLSA-based pedigree assessments
- Differentiate your team’s offerings with verifiable build integrity claims
- Position yourself as the internal reference for SLSA adoption roadmaps
The 12 modules (with all 144 chapters)
- What SLSA solves that prior frameworks don’t
- Key players adopting SLSA today
- The role of transparency in modern software trust
- SLSA vs. SPDX vs. SBOM: when to use which
- How NIST SSDF aligns with SLSA principles
- The Google and OpenSSF origins
- SLSA’s four levels explained concretely
- When Level 1 is enough, and when it’s not
- The cost of false positives in attestation
- Real-world breach paths SLSA prevents
- How regulators are referencing SLSA
- Common misconceptions about implementation cost
- Defining build platform identity
- Capturing start and end time reliably
- Recording build inputs with integrity
- Tracking build environment details
- Storing metadata in provenance format
- Using GitHub Actions for Level 1
- Validating source repository origin
- Signing metadata with GitHub OIDC
- Storing attestations in public repositories
- Auditing for consistency across runs
- Common failure modes at Level 1
- Automating validation checks
- Why hosted platforms are required for Level 2
- Choosing between Cloud Build, CodeBuild, Actions
- Eliminating local execution paths
- Reproducibility requirements defined
- Container image build constraints
- Using Rekor for transparency logs
- Verifying build entry in transparency log
- Signing build outputs with Fulcio
- Configuring OIDC trust chains
- Validating platform compliance automatically
- Integrating with CI/CD pipelines
- Common gaps in Level 2 implementations
- What makes a build reproducible
- Standardizing build environments
- Eliminating timestamps in outputs
- Deterministic compilation techniques
- Container build layer ordering
- Hashing inputs with canonical order
- Using source maps effectively
- Validating output hashes across runs
- Detecting drift in build environments
- Handling dependencies with lockfiles
- Reproducing builds in isolated sandboxes
- Documenting reproducibility for audit
- Defining criticality thresholds for builds
- Implementing two-person approval workflows
- Tracking reviewer attestations
- Using policy engines for automated checks
- Integrating with code review systems
- Logging approvals in transparency logs
- Preventing rollback to weaker levels
- Enforcing build policy across teams
- Auditing verification history
- Scaling Level 4 across large orgs
- Trade-offs between speed and assurance
- Real-world examples from Google and Microsoft
- Understanding SLSA attestation format
- Signing with Sigstore and Fulcio
- Storing signatures in transparency logs
- Verifying signatures automatically
- Using cosign for container signing
- Integrating with image registries
- Keyless signing with OIDC
- Handling certificate rotation
- Multi-party signing workflows
- Attestation metadata schema
- Common signature validation errors
- Best practices for long-term verification
- Generating SBOMs from build outputs
- Linking SBOMs to SLSA attestations
- Using Syft and Grype together
- Validating SBOM completeness
- Publishing SBOMs with provenance
- Consuming SBOMs in downstream services
- Automating SBOM generation in CI
- Handling license compliance via SBOM
- Detecting vulnerable dependencies
- SBOM formats: SPDX vs. CycloneDX
- Storing SBOMs in transparency logs
- Making SBOMs human-readable
- Writing policy rules for SLSA levels
- Using CUE for policy definition
- Integrating with OPA/Gatekeeper
- Blocking non-compliant builds
- Generating policy violation reports
- Onboarding teams to policy standards
- Exempting legacy systems appropriately
- Auditing policy compliance over time
- Scaling policy enforcement across clouds
- Handling false positives gracefully
- Policy versioning and review
- Integrating with security dashboards
- Assessing vendor SLSA compliance
- Requesting attestations from suppliers
- Validating third-party build outputs
- Handling missing or partial attestations
- Using transparency logs for vendor checks
- Integrating with software bills of materials
- Creating vendor onboarding checklists
- Negotiating SLSA requirements in contracts
- Benchmarking vendor maturity levels
- Managing exceptions and waivers
- Automating vendor attestation reviews
- Publishing supplier trust reports
- Identifying compromised builds quickly
- Tracing artifact provenance during incidents
- Validating clean rebuilds post-breach
- Using transparency logs for forensic timelines
- Automating incident playbooks with attestations
- Communicating rebuild status externally
- Rebuilding trust with customers
- Coordinating with security teams
- Documenting remediation steps
- Auditing rebuild integrity
- Integrating with SIEM systems
- Lessons from real-world breaches
- Mapping SLSA to SOC 2 requirements
- Using SLSA for HIPAA compliance
- Integrating with ISO 27001 frameworks
- SLSA and GDPR data provenance
- Meeting financial audit expectations
- Documenting for external auditors
- Handling jurisdictional data rules
- SLSA in government contracts
- Aligning with NIST CSF
- Preparing for DORA compliance
- Regulator-facing documentation templates
- Case study: SLSA in a bank
- Building internal champions
- Creating phased rollout plans
- Measuring adoption progress
- Training engineers on best practices
- Integrating with developer onboarding
- Reducing friction in daily workflows
- Celebrating early wins
- Scaling tooling across orgs
- Maintaining long-term compliance
- Sharing success externally
- Positioning as a career accelerator
- The future of software supply chain standards
How this maps to your situation
- When starting a new build system
- Before onboarding a critical vendor
- After a security audit finding
- When expanding to regulated markets
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 3 hours per module, designed to fit around real project timelines.
How this compares to the alternatives
Unlike generic security courses, this program delivers actionable, step-by-step SLSA implementation guidance with real-world templates and direct applicability to production environments.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.