Skip to contentSkip to content
Verified credentials. On-chain. Forever.Learn more
Ewance
Sign in
Cover image for Secure the Software Supply Chain of an Open-Source SDK
Code

Secure the Software Supply Chain of an Open-Source SDK

FreeVerified credential3 weeksAdvanced

Overview

What this challenge is about.

Secure the Software Supply Chain of an Open-Source SDK. Advanced challenge in code. Writing production code that solves real engineering problems, earn a blo...

CredentialBlockchain-anchored
ShareableLinkedIn-ready
LanguageEnglish
PaceSelf-paced

The Brief

What you'll do, and what you'll demonstrate.

Harden the supply chain of an open-source SDK to SLSA Level 3 and publish SBOM + attestations on every release.

This is not a coding exercise. It is the work a software engineer does between a Jira ticket and a merged PR. That distinction matters to every hiring manager who has seen candidates solve LeetCode problems and none who have shipped production code under real constraints.

When you finish, you will have something most graduates do not: a real-world deliverable, verified by Ewance, that you can show to a hiring manager and say "I did this. Here is the proof."

Earning criteria — what you'll demonstrate

  • Generate SBOMs and attach them to releases
  • Implement SLSA Level 3 build provenance using GitHub Actions
  • Sign commits + releases with Sigstore + Cosign
  • Author a public supply-chain policy users and security researchers trust

Program Fit

Where this fits in your program.

Sharpens the same skills your degree expects you to demonstrate.

Aligned coursework coming soon.

One more thing

You can put a credential on your CV by Friday.