Overview
What this challenge is about.
Audit an open-source SDK, harden its pipeline with signed releases and an SBOM, then earn your verifiable certificate.
The scenario
The developer-tools company (USD 1.2M ARR, around 4,000 downstream applications using the SDK) had a near-miss with a typosquat attempt on a similarly-named package — leadership wants the SDK to be a model citizen, not the next supply-chain headline.
The Brief
What you'll do, and what you'll demonstrate.
Harden the supply chain of an open-source SDK to SLSA Level 3 and publish SBOM + attestations on every release.
Earning criteria — what you'll demonstrate
- Generate SBOMs and attach them to releases
- Implement SLSA Level 3 build provenance using GitHub Actions
- Sign commits + releases with Sigstore + Cosign
- Author a public supply-chain policy users and security researchers trust
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Supply Chain Security
Apply supply chain security to solve real industry problems and demonstrate production-level capability.
- Slsa
Apply slsa to solve real industry problems and demonstrate production-level capability.
- Sbom
Apply sbom to solve real industry problems and demonstrate production-level capability.
- Sigstore
Apply sigstore to solve real industry problems and demonstrate production-level capability.
- Dependency Management
Apply dependency management to solve real industry problems and demonstrate production-level capability.
- Secure Ci Cd
Apply secure ci cd to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles: