New course: Supply Chain Security

News1 min read

Most of the code in an application was not written by the team responsible for it. It comes through dependencies, build tools, base images, CI plugins and AI assistants. Each one adds another point of trust to the software supply chain.

Supply Chain Security is a new SecDim Learn course that teaches developers to examine that whole chain from an attacker’s perspective. It covers the code you write as well as the dependencies, build tools, CI/CD pipelines, registries and AI assistants involved in getting it to production.

The course examines SolarWinds, XZ Utils and event-stream to show how software supply chains are compromised. You then map your own supply chain and apply practical controls: lockfile pinning, artifact signing, SBOM generation and policy-as-code gates that stop a build instead of filing a ticket.

AI supply chain risks have their own section, covering hallucinated packages that attackers can register, insecure code suggestions accepted without review, prompt injection and backdoored models pulled from a registry.

Topics covered include:

  • How SolarWinds, XZ Utils, and event-stream happened, step by step
  • Mapping your own supply chain, from dependency to deploy
  • Lockfile pinning and dependency hygiene
  • Artifact signing
  • SBOM generation
  • Policy-as-code gates in CI/CD
  • AI supply chain attacks: hallucinated packages, insecure code suggestions, prompt injection, backdoored models

Know what goes into your build and where you are placing trust.

:backhand_index_pointing_right: Check it out on SecDim Learn: Learn - SecDim

Questions or comments? Discuss this post on SecDim Community →

Try it yourself

Find, Hack and Fix Your First Vulnerability

Reading about security bugs is one thing — fixing one is how the skill sticks. Play a free challenge from the wargame, no setup required.