
Explore essential supply chain security within DevSecOps for developers, learn key terminology, and apply practical security controls to your pipelines to secure software today.
Explore software supply chain security across all components and processes, from open source code and third-party libraries to cloud infrastructure and development tools, balancing security with business efficiency.
Analyze a scenario where an attacker, after recon, compromises a developer's open source repository account, injects malicious code, and distributes updates that put users and organizations at risk of ransomware.
Learn how software composition analysis helps developers understand dependencies and identify vulnerabilities, enabling patches to minimize risk. See SCA in action with GitHub and Azure DevOps demos.
Identify, assess, remediate, and report vulnerabilities through continuous vulnerability management, prioritizing by severity to focus on high-risk issues, applying patches, updating software, or compensating controls.
Risk management identifies, prioritizes, and treats risks to guide the security strategy, while vulnerability management covers known issues and DevSecOps budgets ensure proactive upskilling.
Identify and prioritize vulnerabilities, patch to the next stable release to mitigate supply chain threats. Test updates to avoid breaking services, review dependencies, and cord removal when patching isn't necessary.
Learn to set up an Azure DevOps project, import code, install the wasp dependency check, and run a python-based pipeline that produces html, csv, and json security reports.
Create and modify an Azure DevOps project. Set up a pipeline, import code, and install the Microsoft Marketplace dependency check, then review the security report for supply chain issues.
Navigate configuring GitHub code security analysis, enable Dependabot and version updates, monitor the dependency graph for vulnerabilities, review pull requests and security.md policies in a demo repo.
Enable and configure Dependabot to generate vulnerability alerts, review findings, merge fixes from pull requests, and show your good work with security policies and GitHub Actions to support the business.
Demonstrates how to run pip audit in a Linux terminal against a requirements.txt based Python project to reveal current library versions, vulnerabilities, and recommended upgrades to strengthen the supply chain.
Install and run the pip audit tool, and review its output to assess package security. Develop awareness of localized security tools and their benefits, including Python, npm, and JavaScript.
Guide developers to secure software supply chains by keeping security simple, enabling pull requests and automated fixes, maintaining an inventory, enforcing least privilege, and auditing development environments.
Learn three capabilities to protect software supply chain security. Explore affordable resources and links to strengthen defenses without costly products.
The Software Supply Chain Security for Developers course takes you from little or no knowledge and shows you how to build security into development projects with practical demonstrations. You will learn the principles of configuring environments in a practical way using minimal lectures and focusing on step by step demonstrations. There are very few courses like this that get straight into the practicalities application security and devsecops. With this capability, you will be able to provide professional and consistent service to your company or clients and help secure your organisation. You will learn to implement security using GitHub and Azure DevOps.
This is a fast-growing area, specialist developers with skills in security are in high demand and using the skills here will enable your career, giving you cyber security experience in Azure DevOps, GitHub and command line. If you are a beginner, this course is for you as it will give you the foundations in a practical way, not theoretical. If you are an experienced practitioner you are now becoming aware of conducting supply chain assessments, this course is absolutely essential for you.
Some of the key areas you will learn are:
Software Supply Chain Security
Building software supply supply chain security into the development using GitHub
Building software supply chain security into the development using Azure DevOps
Practical application security skills
Increase knowledge and skills around DevSecOps
This course will give you the grounding you need to help you learn, retain and replicate the security skills necessary to build and improve your DevSecOps processes. The lectures are to the point and concise because your time, like many practitioners, is precious. All demos can be followed using your own software accounts and replayed time and again as your one-stop security reference.