Skip to content
AtomicReps

Navigation

08/09Security

Software Supply Chain Security.

SBOMs, artifact signing, SLSA framework, dependency attacks, and provenance.

  • Software Supply Chain Security · 1 of 3

    License Compliance & SPDX

    What is the SPDX License Identifier for the MIT license?

  • Software Supply Chain Security · 2 of 3

    SBOMs (SPDX & CycloneDX)

    What identifier scheme does the SBOM ecosystem use to provide a universal, format-agnostic way to reference software packages?

  • Software Supply Chain Security · 3 of 3

    Dependency Confusion & Typosquatting

    Choosing between a 'verify SBOM + VEX at admission' policy and a 'verify SLSA provenance predicate at admission' policy for a regulated workload, what does the provenance check uniquely refuse?

Three of the 1,097 Software Supply Chain Security questions in the bank.

Keep going with Software Supply Chain Security, free
Next topic · 09/09Web Security.