Release and respond

Complete the supply-chain review

Review dependency choice, source controls, CI authority, artifact evidence, vulnerability handling, publishing, and incident readiness as one system.

8 minute lesson

~~~

Supply-chain security is the path from contributor to user. A strong step cannot compensate for an untrusted handoff later.

Trace one release through source approval, dependency resolution, build, artifact, signing, deployment, and update. Verify owners, evidence, and revocation at every handoff. Record gaps with a concrete next improvement.

A project protects source and signs releases, but its desktop updater downloads any file returned by one mutable URL. The final handoff bypasses every earlier control.

A review should follow one release to the user. Remove needless privileged handoffs first, then add verifiable evidence where authority must remain.

Draw one release path from dependency selection through the user update, naming the identity, evidence, and revocation method at every handoff. Save proof for one complete path. Then replace or compromise one test handoff and show exactly which downstream control detects or blocks it.

Lesson completed

Take this course offline

Get every free book and course as PDF and EPUB files.

Get the download library →