Skip to main content

Command Palette

Search for a command to run...

06 - Supply Chain Security - SBOM e Sigstore per Artifact Integrity

Software Bill of Materials (SBOM) standards (SPDX, CycloneDX), Sigstore for artifact signing, verification, provenance, CIA compliance, SolarWinds les

Published
1 min readView as Markdown
F
Love coding and AI

Software Bill of Materials (SBOM) standards (SPDX, CycloneDX), Sigstore for artifact signing, verification, provenance, CIA compliance, SolarWinds lesson.

What you'll learn

  • What an SBOM is and why it's fundamental
  • SBOM standards: CycloneDX and SPDX
  • Sigstore: artifact signing and verification
  • SLSA framework for supply chain integrity
  • Automatic SBOM generation in the CI/CD pipeline

This article is part of the DevSecOps series on federicocalo.dev.


Read the full article

The complete article (15 min read) with code examples, diagrams, and practical exercises is available here:

➡️ 06 - Supply Chain Security - SBOM e Sigstore per Artifact Integrity

https://federicocalo.dev/en/blog/supply-chain-security-sbom-sigstore


By Federico Calò — Software Developer & Technical Writer