Sichere CI/CD-Pipeline für ein FinTech mit Supply-Chain-Härtung
Übersicht
Worum es bei diesem Projekt geht.
Baue eine gehärtete CI/CD-Pipeline für ein FinTech mit Supply-Chain-Security und erhalte ein verifizierbares Zertifikat.
Das Szenario
Das FinTech (Series B, rund 18 Mio. EUR Funding) muss vor der Series C eine SOC 2 Type II vorlegen — Supply-Chain-Härtung ist im Pre-Audit als Top-Gap markiert.
Das Briefing
Was Du tust und was Du zeigst.
Wie baut man eine SLSA-Level-3-konforme CI/CD-Pipeline für 22 GitHub-Repos mit SBOM, Container-Signierung und Supply-Chain-Scans?
Earning criteria — what you'll demonstrate
- SLSA-Framework als Reifegradmodell für CI/CD anwenden
- Pinned Actions und automatisierte Updates kombinieren
- Cosign Keyless OIDC für Container-Signierung produktiv einsetzen
- SBOM-Generierung und -Verifikation in Release-Workflows einbetten
Studienpassung
Wo dies in Dein Studium passt.
Schärft dieselben Fähigkeiten, die Dein Studium von Dir erwartet.
Studienzuordnung folgt in Kürze.
Fähigkeiten
Fähigkeiten, die Du unter Beweis stellst.
Jede taucht auf Deinem verifizierten Zertifikat auf.
- Ci Cd
Apply ci cd to solve real industry problems and demonstrate production-level capability.
- Supply Chain Security
Apply supply chain security to solve real industry problems and demonstrate production-level capability.
- Slsa
Apply slsa to solve real industry problems and demonstrate production-level capability.
- Sbom
Apply sbom to solve real industry problems and demonstrate production-level capability.
- Container Signing
Apply container signing to solve real industry problems and demonstrate production-level capability.
- Github Actions
Apply github actions to solve real industry problems and demonstrate production-level capability.
Karrieren
Berufe, auf die dies Dich vorbereitet.
Echte Berufsbezeichnungen. Echte Skill-Brücken. Wähle die, die Deinem Werdegang am nächsten kommt.
Noch eine Sache