1. Supply Chain Security advanced

    A critical CVE is announced in a widely-used library. Walk me through the first four hours.

    2 min answer vulnerabilitysbomresponsepatching
  2. Supply Chain Security advanced

    A data-protection platform depends on hundreds of third-party libraries. What controls meaningfully reduce supply chain risk, and which are theatre?

    2 min answer druvasupply-chainsbomprovenance
  3. Supply Chain Security advanced

    A developer tools company distributes software used inside thousands of organisations. What supply chain controls matter most, and why is this threat model different from a typical SaaS?

    2 min answer supply-chainprovenancesigningbuild-integrity
  4. Supply Chain Security advanced

    An organisation wants to reduce software supply-chain risk. What actually reduces it, in what order, and which popular measures provide less than they appear to?

    3 min answer supply-chainsbomprovenancedependencies
  5. Supply Chain Security advanced

    Codecov disclosed in 2021 that its Bash Uploader script had been modified to exfiltrate continuous integration environment variables, that the modification had been live since late January and that it was found on 1 April by a customer comparing checksums. What made this compromise so productive for the attacker, and what would have limited it?

    3 min answer codecovsupply chaincisecrets
  6. Supply Chain Security advanced Multiple choice

    Your pipeline signs every container image. Is your supply chain secure?

    2 min answer supply-chainprovenanceverification