06 - Supply Chain Security - SBOM e Sigstore per Artifact Integrity
Software Bill of Materials (SBOM) standards (SPDX, CycloneDX), Sigstore for artifact signing, verification, provenance, CIA compliance, SolarWinds les
Software Bill of Materials (SBOM) standards (SPDX, CycloneDX), Sigstore for artifact signing, verification, provenance, CIA compliance, SolarWinds lesson.
What you'll learn
- What an SBOM is and why it's fundamental
- SBOM standards: CycloneDX and SPDX
- Sigstore: artifact signing and verification
- SLSA framework for supply chain integrity
- Automatic SBOM generation in the CI/CD pipeline
This article is part of the DevSecOps series on federicocalo.dev.
Read the full article
The complete article (15 min read) with code examples, diagrams, and practical exercises is available here:
➡️ 06 - Supply Chain Security - SBOM e Sigstore per Artifact Integrity
https://federicocalo.dev/en/blog/supply-chain-security-sbom-sigstore
By Federico Calò — Software Developer & Technical Writer