Skip to main content

Software Supply Chain Security: DAST, SBOM, SLSA

Learn to run DAST with OWASP ZAP, generate SBOMs with Syft, scan with Grype, and sign and verify images with Cosign and SLSA provenance.

~3 hours
10 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why Static Testing Is Not Enough

The gap between code that passes and a system that holds SAST and SCA read code and dependency lists, but neither one ever runs your application.

Running DAST with OWASP ZAP

Choosing between baseline and full scans OWASP ZAP (Zed Attack Proxy) is the most widely used open source DAST tool.

Generating SBOMs with Syft

What an SBOM is and why it matters An SBOM (Software Bill of Materials) is the ingredient list of your software: every component, version, license...

Scanning SBOMs for Vulnerabilities with Grype

How Grype turns an inventory into findings Grype matches the components in an SBOM or image against vulnerability databases such as the GitHub...

Learning from SolarWinds, XZ Utils, and Trivy

SolarWinds: the build system was the target In 2020 attackers, widely attributed to Russian state hackers, broke into SolarWinds' build environment...

Signing and Verifying Artifacts with Cosign

How keyless signing works Cosign signs container images and other artifacts.

Skills You'll Master

DASTSBOMSUPPLY-CHAIN-SECURITYCOSIGNSLSA

Curriculum Index10 topics

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • Application Security Engineer

    ₹14L - ₹32L a year

    Growing
  • Security Engineer

    ₹14L - ₹35L a year

    Growing
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

SAST reads source code without running it, so it finds insecure patterns early. DAST attacks a running application from the outside, so it finds runtime and configuration problems such as missing headers or debug mode. Most teams need both.

A Software Bill of Materials is a machine readable list of every component inside your software. When a new vulnerability is announced, you search your SBOMs and know which products are affected in minutes, instead of searching repositories by hand.

No. A signature proves who built the artifact and that it was not changed afterwards. It says nothing about whether the code is free of bugs or backdoors, so signing works alongside scanning, not instead of it.

Build level 2 is a realistic first target: a hosted build service that signs provenance for you. Level 3 adds stronger isolation between builds and is worth the effort for your most critical software.