Skip to contentSkip to content
Verified credentials. On-chain. Forever.Learn more
Ewance
Sign in
Cover image for Design a SLSA-Aligned, Signed Release Pipeline for an Apache Project
Design

Design a SLSA-Aligned, Signed Release Pipeline for an Apache Project

FreeVerified credential2 weeksAdvanced

Overview

What this challenge is about.

Design a SLSA Level 3 release pipeline with hermetic builds and Sigstore-signed artifacts. Earn a verifiable certificate.

The scenario

The Apache Software Foundation stewards hundreds of volunteer-run projects whose releases are consumed directly by enterprises, making each project's build pipeline a high-value target; this particular data-processing engine ships frequently and has already absorbed two typosquat dependency attempts in six months.

CredentialBlockchain-anchored
ShareableLinkedIn-ready
LanguageEnglish
PaceSelf-paced

The Brief

What you'll do, and what you'll demonstrate.

Design a release-pipeline hardening proposal that brings an Apache project to SLSA Level 3 alignment—signed artifacts, build provenance, hermetic builds, and two-person release review—without disrupting its volunteer release cadence.

Earning criteria — what you'll demonstrate

  • Map a real release pipeline against the SLSA v1.0 framework and translate gaps into prioritized, justified changes
  • Design hermetic, provenance-emitting builds and Sigstore-based artifact signing that integrate with an existing GitHub Actions workflow
  • Write an operator runbook precise enough that a maintainer can verify provenance and rotate keys without coaching
  • Shape a security change so it fits open-source governance norms—pull-request delivery, two-person review, and mailing-list lazy consensus

Program Fit

Where this fits in your program.

Sharpens the same skills your degree expects you to demonstrate.

Aligned coursework coming soon.

Careers

Career paths this challenge builds toward

Completing this challenge demonstrates skills that transfer directly to these roles:

Software Supply-Chain Security Engineer

This challenge mirrors the core work of securing a build-and-release pipeline: mapping to SLSA, adding signing and provenance, and proving artifacts are tamper-evident. You leave with a portfolio-grade hardening proposal that demonstrates exactly the judgment this role requires.

This challenge sharpens

  • supply-chain
  • slsa
  • sigstore

Release Engineer

You design merge-ready pipeline changes that add provenance and signing without breaking an existing release cadence—the central tension a release engineer manages. The deliverables show you can harden a pipeline while keeping shipping smooth and reviewable.

This challenge sharpens

  • release-engineering
  • supply-chain
  • sigstore

Open-Source Security Program Lead

Beyond the technical fix, you must win consensus inside a volunteer foundation through pull requests and mailing-list norms. This bridges to a role that drives security policy across community-governed projects where adoption depends as much on governance fluency as on engineering.

This challenge sharpens

  • policy-design
  • oss-contribution
  • slsa

One more thing

You can put a credential on your CV by Friday.