Information & Communications Technology

Secure Software Supply Chain and Software Bill of Materials Practice

Learn to secure build pipelines end to end: generate software bills of materials, verify component provenance, and detect tampering before dependencies reach production.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

A single compromised open-source package or a tampered build step can silently poison every product that depends on it, which is why software supply chain attacks now draw as much attention as application vulnerabilities themselves. This course teaches you to secure the path from source code to running artifact. You will generate and consume software bills of materials in CycloneDX and SPDX formats, verify component provenance against frameworks such as SLSA, and harden build pipelines against injected dependencies and unsigned artifacts. Practical sessions walk through scanning open-source components for known vulnerabilities and licence conflicts, signing build outputs, and setting policy gates that block unverified packages from reaching production. You will also design an incident response path for the moment a compromised dependency is disclosed, including how to identify every affected build quickly using SBOM data already on file, so remediation starts in hours rather than weeks.

Expected Learning Outcomes

01

Generate software bills of materials in CycloneDX and SPDX formats for applications built from mixed open-source and internal components.

02

Assess component provenance and build integrity against SLSA framework levels appropriate to the system's risk profile.

03

Configure dependency scanning to flag known vulnerabilities and licence conflicts before code merges.

04

Sign build artifacts and verify signatures at deployment to detect tampering introduced after the build stage.

05

Set policy gates in continuous integration pipelines that block unverified or unapproved third-party packages.

06

Use existing SBOM records to identify every affected build within hours of a dependency compromise disclosure.

07

Design a vendor questionnaire that captures a supplier's own supply chain security practices before onboarding.

Who Should Attend

01

DevSecOps engineers responsible for build pipeline security

02

Application security teams managing open-source dependency risk

03

Software engineering leads accountable for release integrity

04

Procurement and vendor risk staff evaluating third-party software

05

Compliance officers preparing for emerging SBOM disclosure requirements

06

Platform teams operating shared continuous integration infrastructure

Course Modules

Select any module to see its sessions and points.

01

Mapping the Software Supply Chain

2 sessions · 8 points

Session 1Identifying Components and Dependencies

  • Inventory direct and transitive dependencies across an application's full dependency tree using automated tooling.
  • Classify components by origin, licence type and maintenance status to reveal hidden risk concentrations.
  • Distinguish first-party code, vendored libraries and dynamically pulled containers within a single build.
  • Map build and deployment infrastructure to identify every stage where an attacker could inject unauthorised code.

Session 2Understanding Supply Chain Attack Patterns

  • Analyse how dependency confusion attacks exploit naming collisions between internal and public package registries.
  • Examine how compromised maintainer accounts have been used to publish malicious package updates.
  • Assess the risk introduced by unpinned version ranges that silently pull in unreviewed code changes.
  • Review how build system compromises can inject malicious steps without altering source code repositories.
02

Producing and Consuming Software Bills of Materials

2 sessions · 8 points

Session 1Generating SBOMs in CycloneDX and SPDX

  • Generate a component-level SBOM automatically as part of the build pipeline rather than as a manual afterthought.
  • Choose between CycloneDX and SPDX formats based on downstream tooling and customer contractual requirements.
  • Enrich SBOM records with licence and vulnerability metadata pulled from authoritative databases.
  • Version and store SBOM artifacts alongside their corresponding build so historical audits remain possible.

Session 2Using SBOMs for Risk Response

  • Query stored SBOM data to identify every product build containing a newly disclosed vulnerable component.
  • Prioritise remediation across affected builds based on exposure, deployment status and customer impact.
  • Share relevant SBOM extracts with customers or regulators without exposing unrelated proprietary details.
  • Automate alerts that trigger when a component in an in-support SBOM receives a new vulnerability disclosure.
03

Hardening Build and Release Pipelines

2 sessions · 8 points

Session 1Provenance and Artifact Signing

  • Apply SLSA framework levels to determine the provenance guarantees required for each build pipeline.
  • Sign build artifacts cryptographically and verify signatures automatically before deployment proceeds.
  • Isolate build environments so a compromised dependency cannot alter the pipeline that produces the next release.
  • Record build provenance metadata, including source commit, builder identity and build parameters, for every release.

Session 2Policy Gates and Dependency Governance

  • Configure automated gates that block merges or deployments containing packages with known critical vulnerabilities.
  • Set an approved-registry policy that prevents dependency confusion attacks against internal package names.
  • Pin dependency versions deliberately and manage upgrades through a reviewed, scheduled process.
  • Establish an exception process for cases where a flagged dependency has no available secure alternative.
04

Governance, Response and Continuous Improvement

2 sessions · 8 points

Session 1Vendor and Third-Party Assurance

  • Design a supplier questionnaire that assesses a vendor's own build integrity and vulnerability disclosure practices.
  • Require SBOM delivery as a contractual condition for critical third-party software components.
  • Assess open-source project health indicators, such as maintainer activity and issue response time, before adoption.
  • Review contractual and licensing obligations that arise from redistributing open-source components.

Session 2Incident Response for Supply Chain Compromise

  • Run a tabletop exercise simulating disclosure of a critical vulnerability in a widely used shared dependency.
  • Define escalation paths that connect security, engineering and customer communications during a supply chain incident.
  • Rebuild and re-sign affected artifacts from a verified clean source once a compromise is contained.
  • Capture lessons learned into updated policy gates and dependency governance rules after each incident.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course