Free course
Software Supply Chain Security Course
Secure dependencies, repositories, CI workflows, artifacts, releases, vulnerability handling, publishing authority, and dependency incident response.
Prerequisites: Security Fundamentals, Git and Testing JavaScript Applications
Your progress
of lessons completed.
Course completed.
What you'll learn
Trace and strengthen the complete path from dependency choice and source review through a verifiable artifact and controlled release.
Take this course offline
Subscribe to my newsletter to get every free book and course in PDF and EPUB format.
Get the downloadsCourse contents
Know what you build with
Map dependencies, lock resolution, inspect package behavior, and choose trusted code deliberately.
Protect source and CI
Control repository access, reviews, secrets, workflow permissions, and untrusted contributions.
Build verifiable artifacts
Use clean builds, SBOMs, provenance, signatures, and hardened container images.
Handle vulnerabilities
Scan completely, triage reachability, patch transitive code, and coordinate disclosure.
Release and respond
Protect publishing, verify deployment artifacts, and respond to compromised dependencies.