Table of Contents

Build a release process you can inspect and verify. This course follows one fictional calculator release from a dependency change to a consumer decision. You will record what changed, narrow the build’s authority, generate a component inventory, inspect provenance, and reject a tampered release.

Audience and Prerequisites

Audience: Developers, release engineers, and security staff who maintain repositories or review packages. The guided local path needs Python 3.10 or later and a terminal. Git and a GitHub account are optional. The hosted path needs a disposable repository where you control Actions settings.

Time: Four to six hours for the lessons, one hour for the lab, and two hours for the capstone. The local tampering exercise has no cloud cost. Do not use production credentials or releases.

Learning Outcomes

After the course, you will:

  • Review a dependency change and document its direct and transitive effects.
  • Inspect a sample SBOM, then generate one from your own project with Syft if you take the optional tool path.
  • Limit pipeline permissions and separate untrusted pull request work from release work.
  • Interpret a Scorecard finding and make a review decision.
  • Read SLSA provenance fields and compare an artifact with an expected source and builder. The hosted path adds signed attestation verification.
  • Reject a changed release in a controlled local investigation.

Lesson Order

StagePagePractical skill
1Review Dependencies and Build an SBOMCreate a dependency decision record and component inventory
2Limit Pipeline Authority and Use ScorecardReview token scope and record a prioritized Scorecard finding
3Verify Provenance and AttestationsMatch artifact digest, source, and workflow to a release policy
4Tampered Release LabRun a local rejection test and explain its trust boundary
5Knowledge Check and answer keyAnswer scenario questions and correct mistakes
6Release Gate Capstone and reference packetProduce a release decision packet and test a failure path

Complete the pages in order. Lessons 1 through 3 build the review method. The lab then shows a concrete failure. The capstone asks you to apply the method to a fresh release decision.

What You Will Produce

Keep one release packet with a dependency review, SBOM component, permissions table, Scorecard finding, expected provenance identity, artifact digest, lab result, and release decision. The lessons and lab archive supply the local examples and evidence. Its Scorecard and provenance files are clearly labeled teaching fixtures, not live tool results. A passing checksum alone is an integrity check. Publisher identity needs a separate signed attestation check.

Safe Practice Paths

Local path: Download the lab archive , extract it, and use Python to inspect the fictional dependency change, SBOM, Scorecard result, provenance statement, policy, and release files. All local pass criteria use these fixtures. Record “not run” for Syft, GitHub Actions, and signed attestation checks you did not execute.

Hosted path: Use a disposable GitHub repository. Enable Actions, run only the example workflows after reviewing every action reference, then delete the repository and any test artifact when done. GitHub’s secure use guidance explains why workflow code and tokens need careful review.

Start with dependency review and SBOMs . Return to Courses and Playbooks for other paths.