Course

Software Supply Chain Security Foundations: From Components to Trusted Releases

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Intermediate
Modules 4
Lessons 8
Time 5 hr 20 min
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
Trusted releases depend on the full software supply chainA flow connects source, components, protected build, evidence, release, and ongoing response.SOFTWARE SUPPLY CHAIN SECURITYFrom components to trusted releasesSOURCECOMPONENTSBUILDEVIDENCERELEASESecurity comes from the trust decisions and checks across the chain—not one artifact or scanner.

About this course

This intermediate course teaches developers, engineering leaders, platform teams, security practitioners, and software buyers how to reason about the path from source component to deployed software. Learners identify the trust boundaries in that path, build an inventory that supports decisions, protect build and release systems, evaluate evidence such as provenance, and respond when a dependency or supplier risk changes.

The course is tool- and ecosystem-neutral. It does not promise that a software bill of materials, signature, or scanner makes software safe by itself. Instead, it shows how each control contributes evidence, where it can fail, and how to sequence improvements that engineering teams can operate.

What you'll learn

  • Map a software supply chain and identify the source, dependency, build, release, supplier, and deployment trust boundaries that require evidence.
  • Select proportionate controls for component inventory, dependency acquisition, build integrity, secret handling, and release authorization.
  • Interpret an SBOM, provenance record, signature, policy result, and vulnerability finding without overstating what each proves.
  • Create a response and improvement plan that links a supply-chain risk scenario to accountable actions, verification evidence, and review dates.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Basic software delivery knowledge — Learners should understand source control, dependencies, builds, testing, deployment, and the difference between an application and a reusable software component.

Course content