1. Supply-Chain Provenance intermediate

    A prospective government customer asks your team to attest that your software is developed in a secure environment and that you maintain provenance data for the source code you ship. Your pipeline builds on shared runners, release tags are pushed by whoever is on duty, and nothing is attested today. Walk me through how you would answer them.

    3 min answer provenancessdfattestationslsa
  2. Supply-Chain Provenance advanced

    An auditor asks you to prove that the container running in production is the one that passed security scanning three weeks ago. What must be true?

    2 min answer supply-chainauditprovenance
  3. Supply-Chain Provenance advanced

    The xz-utils backdoor disclosed on 29 March 2024 (CVE-2024-3094) was present in the release tarballs for versions 5.6.0 and 5.6.1 but not in the equivalent state of the public git repository: the malicious build-to-host.m4 macro shipped only in the distributed archive and activated a payload hidden in test fixtures during the build. Which assumption in a normal supply-chain pipeline does this defeat, and what would have caught it?

    3 min answer xzsupply-chainprovenancereproducible-builds
  4. Supply-Chain Provenance advanced

    What does provenance add beyond signing, and what makes it usable rather than ceremonial?

    2 min answer provenanceattestationverificationinventory
  5. Supply-Chain Provenance intermediate

    Your pipeline now generates an SBOM for every build. A critical vulnerability is announced in a transitive dependency. Can you answer the question that matters?

    2 min answer sbomvulnerabilityresponse