Skip to content
AtomicReps

Navigation

08/09Security

Software Supply Chain Security.

SBOMs, artifact signing, SLSA framework, dependency attacks, and provenance.

  • Software Supply Chain Security · 1 of 3

    License Compliance & SPDX

    What is the SPDX License Identifier for the MIT license?

  • Software Supply Chain Security · 2 of 3

    SBOMs (SPDX & CycloneDX)

    What identifier scheme does the SBOM ecosystem use to provide a universal, format-agnostic way to reference software packages?

  • Software Supply Chain Security · 3 of 3

    Dependency Confusion & Typosquatting

    Choosing between a 'verify SBOM + VEX at admission' policy and a 'verify SLSA provenance predicate at admission' policy for a regulated workload, what does the provenance check uniquely refuse?

Three of the 1,097 Software Supply Chain Security questions.

Keep going with Software Supply Chain Security, free
Next topic · 09/09Web Security.