DevSecOps EngineerAvailable

CI/CD Security Hardening

About this course

Your delivery pipeline is a privileged system with write access to production. This course covers supply chain attacks, secret leakage, OIDC federation, signed artifacts with Sigstore, and the SLSA framework for verifiable builds.

What you will learn

  • Supply chain attack anatomy and real-world incidents
  • Replacing long-lived secrets with OIDC federation in CI
  • GitHub Actions hardening: permissions, pinning, and Dependabot
  • Artifact signing and provenance with cosign and Sigstore
  • Dependency pinning and lockfile integrity verification
  • SLSA framework levels and how to reach Level 3
  • Pipeline-as-code security review workflows
  • Secrets scanning and pre-commit hooks

Your instructor

Ayodele Ajayi

Principal Engineer

Principal Engineer based in Kent, UK, with extensive experience across cloud-native security, platform engineering, and distributed systems. Ayodele has led engineering teams at scale and writes about what he learns — with a bias towards things that actually work in production.

Continue building your skills in this area.

Zero Trust Architecture from Scratch

8 lessons

Container Scanning Essentials

8 lessons