DevSecOps EngineerAvailable
CI/CD Security Hardening
About this course
Your delivery pipeline is a privileged system with write access to production. This course covers supply chain attacks, secret leakage, OIDC federation, signed artifacts with Sigstore, and the SLSA framework for verifiable builds.
What you will learn
- Supply chain attack anatomy and real-world incidents
- Replacing long-lived secrets with OIDC federation in CI
- GitHub Actions hardening: permissions, pinning, and Dependabot
- Artifact signing and provenance with cosign and Sigstore
- Dependency pinning and lockfile integrity verification
- SLSA framework levels and how to reach Level 3
- Pipeline-as-code security review workflows
- Secrets scanning and pre-commit hooks
Your instructor
Ayodele Ajayi
Principal Engineer
Principal Engineer based in Kent, UK, with extensive experience across cloud-native security, platform engineering, and distributed systems. Ayodele has led engineering teams at scale and writes about what he learns — with a bias towards things that actually work in production.