Design a SLSA-Aligned, Signed Release Pipeline for an Apache Project
Overview
What this challenge is about.
Design a SLSA-Aligned, Signed Release Pipeline for an Apache Project. Advanced challenge in design. Designing real products under real constraints, earn a bl...
The Brief
What you'll do, and what you'll demonstrate.
Design a release-pipeline hardening proposal that brings an Apache project to SLSA Level 3 alignment—signed artifacts, build provenance, hermetic builds, and two-person release review—without disrupting its volunteer release cadence.
This is not a design exercise. It is the work a product designer does between a brief and a shipped interface. That distinction matters to every hiring manager who has seen candidates redesign Spotify's homepage and none who have worked under real product constraints.
When you finish, you will have something most graduates do not: a real-world deliverable, verified by Ewance, that you can show to a hiring manager and say "I did this. Here is the proof."
Earning criteria — what you'll demonstrate
- Map a real release pipeline against the SLSA v1.0 framework and translate gaps into prioritized, justified changes
- Design hermetic, provenance-emitting builds and Sigstore-based artifact signing that integrate with an existing GitHub Actions workflow
- Write an operator runbook precise enough that a maintainer can verify provenance and rotate keys without coaching
- Shape a security change so it fits open-source governance norms—pull-request delivery, two-person review, and mailing-list lazy consensus
Program Fit
Where this fits in your program.
Sharpens the same skills your degree expects you to demonstrate.
Aligned coursework coming soon.
Skills
Skills you'll demonstrate.
Each one shows up on your verified credential.
- Supply Chain
Apply supply chain to solve real industry problems and demonstrate production-level capability.
- Slsa
Apply slsa to solve real industry problems and demonstrate production-level capability.
- Sigstore
Apply sigstore to solve real industry problems and demonstrate production-level capability.
- Oss Contribution
Apply oss contribution to solve real industry problems and demonstrate production-level capability.
- Release Engineering
Apply release engineering to solve real industry problems and demonstrate production-level capability.
- Policy Design
Apply policy design to solve real industry problems and demonstrate production-level capability.
Careers
Career paths this challenge builds toward
Completing this challenge demonstrates skills that transfer directly to these roles:
Software Supply-Chain Security Engineer
This challenge mirrors the core work of securing a build-and-release pipeline: mapping to SLSA, adding signing and provenance, and proving artifacts are tamper-evident. You leave with a portfolio-grade hardening proposal that demonstrates exactly the judgment this role requires.
This challenge sharpens
- supply-chain
- slsa
- sigstore
Release Engineer
You design merge-ready pipeline changes that add provenance and signing without breaking an existing release cadence—the central tension a release engineer manages. The deliverables show you can harden a pipeline while keeping shipping smooth and reviewable.
This challenge sharpens
- release-engineering
- supply-chain
- sigstore
Open-Source Security Program Lead
Beyond the technical fix, you must win consensus inside a volunteer foundation through pull requests and mailing-list norms. This bridges to a role that drives security policy across community-governed projects where adoption depends as much on governance fluency as on engineering.
This challenge sharpens
- policy-design
- oss-contribution
- slsa