Software Supply Chain Security: DAST, SBOM, SLSA
Learn to run DAST with OWASP ZAP, generate SBOMs with Syft, scan with Grype, and sign and verify images with Cosign and SLSA provenance.
What You'll Learn
Understanding Why Static Testing Is Not Enough
The gap between code that passes and a system that holds SAST and SCA read code and dependency lists, but neither one ever runs your application.
Running DAST with OWASP ZAP
Choosing between baseline and full scans OWASP ZAP (Zed Attack Proxy) is the most widely used open source DAST tool.
Generating SBOMs with Syft
What an SBOM is and why it matters An SBOM (Software Bill of Materials) is the ingredient list of your software: every component, version, license...
Scanning SBOMs for Vulnerabilities with Grype
How Grype turns an inventory into findings Grype matches the components in an SBOM or image against vulnerability databases such as the GitHub...
Learning from SolarWinds, XZ Utils, and Trivy
SolarWinds: the build system was the target In 2020 attackers, widely attributed to Russian state hackers, broke into SolarWinds' build environment...
Signing and Verifying Artifacts with Cosign
How keyless signing works Cosign signs container images and other artifacts.
Skills You'll Master
Curriculum Index10 topics
Understanding Why Static Testing Is Not Enough
The gap between code that passes and a system that holds SAST and SCA read code and dependency lists, but neither one...
Running DAST with OWASP ZAP
Choosing between baseline and full scans OWASP ZAP (Zed Attack Proxy) is the most widely used open source DAST tool.
Generating SBOMs with Syft
What an SBOM is and why it matters An SBOM (Software Bill of Materials) is the ingredient list of your software: every...
Scanning SBOMs for Vulnerabilities with Grype
How Grype turns an inventory into findings Grype matches the components in an SBOM or image against vulnerability...
Learning from SolarWinds, XZ Utils, and Trivy
SolarWinds: the build system was the target In 2020 attackers, widely attributed to Russian state hackers, broke into...
Signing and Verifying Artifacts with Cosign
How keyless signing works Cosign signs container images and other artifacts.
Understanding SLSA Provenance
What SLSA levels mean SLSA (Supply-chain Levels for Software Artifacts, pronounced "salsa") is a framework for how much...
Building the Complete Pipeline
The stages and why the order matters The pipeline runs cheap, fast checks first and signs only after everything has...
Running the Hands-On Lab: Supply Chain Security on Your Laptop
Before you start This lab runs entirely on your machine with Docker.
Quick Reference and Common Mistakes
Quick reference Common mistakes Running a full ZAP scan against production or a shared staging environment is the most...
Career Impact
Roles that use the skills in this module.
- High Demand
DevSecOps Engineer
₹12L - ₹30L a year
- Growing
Application Security Engineer
₹14L - ₹32L a year
- Growing
Security Engineer
₹14L - ₹35L a year
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
SAST reads source code without running it, so it finds insecure patterns early. DAST attacks a running application from the outside, so it finds runtime and configuration problems such as missing headers or debug mode. Most teams need both.
A Software Bill of Materials is a machine readable list of every component inside your software. When a new vulnerability is announced, you search your SBOMs and know which products are affected in minutes, instead of searching repositories by hand.
No. A signature proves who built the artifact and that it was not changed afterwards. It says nothing about whether the code is free of bugs or backdoors, so signing works alongside scanning, not instead of it.
Build level 2 is a realistic first target: a hosted build service that signs provenance for you. Level 3 adds stronger isolation between builds and is worth the effort for your most critical software.