Overview
What this challenge is about.
Audit a HealthTech pipeline, implement SLSA 3 controls with provenance and Cosign signing, then validate admission policies. Earn a verifiable certificate.
The scenario
The health-tech SaaS (Series D, HITRUST-certified) has 4 customer contracts gated on SLSA-3 attestation as of Q3 — the work has a hard external deadline.
The Brief
What you'll do, and what you'll demonstrate.
Harden a container supply chain to SLSA Level 3 with provenance, signing, and admission-policy enforcement, validated end-to-end on a representative service.
Earning criteria — what you'll demonstrate
- Read the SLSA 1.0 specification and apply it to a real pipeline
- Generate, sign, and verify provenance with Sigstore tooling
- Enforce admission policy that rejects unsigned or unprovenanced artifacts
- Communicate supply-chain hygiene to non-technical procurement reviewers
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Supply Chain Security
Apply supply chain security to solve real industry problems and demonstrate production-level capability.
- Slsa
Apply slsa to solve real industry problems and demonstrate production-level capability.
- Sigstore
Apply sigstore to solve real industry problems and demonstrate production-level capability.
- Cosign
Apply cosign to solve real industry problems and demonstrate production-level capability.
- Policy Enforcement
Apply policy enforcement to solve real industry problems and demonstrate production-level capability.
- Admission Controllers
Apply admission controllers to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles: