New course: Supply Chain Security
Most of the code in an application was not written by the team responsible for it. It comes through dependencies, build tools, base images, CI plugins and AI assistants. Each one adds another point of trust to the software supply chain.
Supply Chain Security is a new SecDim Learn course that teaches developers to examine that whole chain from an attacker’s perspective. It covers the code you write as well as the dependencies, build tools, CI/CD pipelines, registries and AI assistants involved in getting it to production.
The course examines SolarWinds, XZ Utils and event-stream to show how software supply chains are compromised. You then map your own supply chain and apply practical controls: lockfile pinning, artifact signing, SBOM generation and policy-as-code gates that stop a build instead of filing a ticket.
AI supply chain risks have their own section, covering hallucinated packages that attackers can register, insecure code suggestions accepted without review, prompt injection and backdoored models pulled from a registry.
Topics covered include:
- How SolarWinds, XZ Utils, and event-stream happened, step by step
- Mapping your own supply chain, from dependency to deploy
- Lockfile pinning and dependency hygiene
- Artifact signing
- SBOM generation
- Policy-as-code gates in CI/CD
- AI supply chain attacks: hallucinated packages, insecure code suggestions, prompt injection, backdoored models
Know what goes into your build and where you are placing trust.
Check it out on SecDim Learn: Learn - SecDim
