Software Build Integrity and Dependency Trust (Paperback)
Lingua: inglese
Editore: Independently Published, 2026
- Brossura
- Nuovo

Da: Grand Eagle Retail, Bensenville, IL, U.S.A.Grand Eagle Retail
Venditore AbeBooks dal 12 ottobre 2005
Condizione: Nuovo
EUR 20,13
Quantità: 1 disponibile
Aggiungi al carrelloDescrizione dell’articolo da parte del venditore
Paperback. You reviewed the code. You scanned the dependencies. You signed the release. But can you prove that the software running in production is the exact software your organization intended to ship?Modern applications are created through far more than source code. Repositories, package registries, open-source projects, CI runners, reusable workflows, build images, compilers, caches, cloud identities, signing systems, artifact stores, containers, and deployment controllers all influence what eventually reaches production.Every one of those systems creates a trust decision.Software Build Integrity and Dependency Trust is a practical guide to designing software delivery systems in which those decisions can be verified rather than merely assumed.Instead of treating software supply-chain security as a collection of scanners and compliance checkboxes, this book shows how to build a measurable chain of evidence from authorized change to production deployment.Inside, you'll learn how to: Protect repositories, branches, tags, maintainers, workflow files, and release pathsControl third-party components before they enter sensitive environmentsDefend against namespace confusion, malicious updates, compromised maintainers, and unsafe transitive relationshipsTreat CI/CD platforms as privileged security infrastructureSeparate untrusted validation, trusted compilation, publication, signing, promotion, and deploymentBuild reproducible, hermetic, isolated, and evidence-producing environmentsUse immutable digests to identify exactly what was tested, approved, distributed, and deployedDesign signing systems around identities and policy rather than shared long-lived secretsGenerate and use SBOMs, VEX information, attestations, and machine-readable evidenceApply SLSA concepts without turning maturity levels into meaningless badgesEnforce promotion and deployment decisions through policy as codeReplace permanent automation credentials with short-lived workload identitiesPrepare for compromised runners, malicious components, stolen signers, poisoned caches, and altered release workflowsBuild forensic evidence that allows responders to quickly determine where affected components were built and deployedScale strong controls across hundreds or thousands of repositories without creating release bureaucracyReal-world incidents involving SolarWinds, Codecov, PyTorch, and xz Utils demonstrate how different parts of the delivery chain can fail-and why no single security control is enough.The book also includes a practical maturity model, a structured learning path, a 90-day implementation playbook, a seven-layer reference architecture, a ten-question architecture review, a decision matrix, and detailed operational checklists that teams can adapt to real environments.Whether you're a software engineer, DevOps or DevSecOps professional, platform engineer, cloud engineer, security engineer, architect, SRE, engineering leader, or technology risk professional, this book will help you answer the question that increasingly matters: Why should this exact software be trusted to run?Build faster when appropriate. Verify before trust. Make evidence part of the delivery system. This item is printed on demand. Shipping may be from multiple locations in the US or from the UK, depending on stock availability. …
Codice articolo 9798171782542
- Titolo
- Software Build Integrity and Dependency Trust (Paperback)
- Autore
- Rion Frost
- Editore
- Independently Published
- Anno di pubblicazione
- 2026
- Condizione
- new
- Rilegatura
- Paperback
- Lingua
- inglese
- ISBN 13
- 9798171782542
You reviewed the code. You scanned the dependencies. You signed the release. But can you prove that the software running in production is the exact software your organization intended to ship?
Modern applications are created through far more than source code. Repositories, package registries, open-source projects, CI runners, reusable workflows, build images, compilers, caches, cloud identities, signing systems, artifact stores, containers, and deployment controllers all influence what eventually reaches production.
Every one of those systems creates a trust decision.
Software Build Integrity and Dependency Trust is a practical guide to designing software delivery systems in which those decisions can be verified rather than merely assumed.
Instead of treating software supply-chain security as a collection of scanners and compliance checkboxes, this book shows how to build a measurable chain of evidence from authorized change to production deployment.
Inside, you'll learn how to:
- Protect repositories, branches, tags, maintainers, workflow files, and release paths
- Control third-party components before they enter sensitive environments
- Defend against namespace confusion, malicious updates, compromised maintainers, and unsafe transitive relationships
- Treat CI/CD platforms as privileged security infrastructure
- Separate untrusted validation, trusted compilation, publication, signing, promotion, and deployment
- Build reproducible, hermetic, isolated, and evidence-producing environments
- Use immutable digests to identify exactly what was tested, approved, distributed, and deployed
- Design signing systems around identities and policy rather than shared long-lived secrets
- Generate and use SBOMs, VEX information, attestations, and machine-readable evidence
- Apply SLSA concepts without turning maturity levels into meaningless badges
- Enforce promotion and deployment decisions through policy as code
- Replace permanent automation credentials with short-lived workload identities
- Prepare for compromised runners, malicious components, stolen signers, poisoned caches, and altered release workflows
- Build forensic evidence that allows responders to quickly determine where affected components were built and deployed
- Scale strong controls across hundreds or thousands of repositories without creating release bureaucracy
Real-world incidents involving SolarWinds, Codecov, PyTorch, and xz Utils demonstrate how different parts of the delivery chain can fail—and why no single security control is enough.
The book also includes a practical maturity model, a structured learning path, a 90-day implementation playbook, a seven-layer reference architecture, a ten-question architecture review, a decision matrix, and detailed operational checklists that teams can adapt to real environments.
Whether you're a software engineer, DevOps or DevSecOps professional, platform engineer, cloud engineer, security engineer, architect, SRE, engineering leader, or technology risk professional, this book will help you answer the question that increasingly matters:
Why should this exact software be trusted to run?
Build faster when appropriate. Verify before trust. Make evidence part of the delivery system.
"Riassunto" può appartenere a un’altra edizione di questo titolo.
Grand Eagle Retail
Bensenville, IL, U.S.A.
Venditore AbeBooks dal 12 ottobre 2005
Tariffe di spedizione nazionale per U.S.A.
| Articolo | Da 6 a 14 giorni lavorativi | Da 6 a 16 giorni lavorativi |
|---|---|---|
| Primo articolo | EUR 0,00 | EUR 0,00 |
Metodi di pagamento
Informazioni sull’azienda del venditore
APOLLO ONLINE CORP.
605 Geddes Street
Wilmington, DE U.S.A. 19805
Condizioni di vendita
We guarantee the condition of every book as it¿s described on the Abebooks web sites. If you¿ve changed
your mind about a book that you¿ve ordered, please use the Ask bookseller a question link to contact us
and we¿ll respond within 2 business days.
Books ship from California and Michigan.
Diritto di recesso
Se sei un consumatore puoi recedere dal contratto in conformità con quanto segue. Per Consumatore si intende qualsiasi persona fisica che agisce per scopi estranei alla propria attività commerciale, imprenditoriale, artigianale o professionale.
Informazioni sul diritto di recesso
Diritto legale di recesso
Hai il diritto di recedere dal presente contratto entro 14 giorni senza fornire alcuna motivazione.
Il periodo di recesso scade dopo 14 giorni dal giorno in cui tu o una terza parte, diversa dal vettore e da te indicata, acquisisce il possesso fisico dell'ultimo bene o dell'ultimo lotto o pezzo.
Per esercitare il diritto di recesso, compila e invia elettronicamente una dichiarazione esplicita sul nostro sito Web, alla voce “I miei acquisti” nella sezione “Mio account”. Ti comunicheremo senza indugio una conferma di ricezione di tale recesso su un supporto durevole (ad es. via e-mail).
Per rispettare il termine di recesso, è sufficiente inviare la comunicazione relativa all'esercizio del diritto di recesso prima della scadenza del periodo di recesso stesso.
Effetti del recesso
In caso di recesso dal presente contratto, ti rimborseremo tutti i pagamenti ricevuti, compresi i costi di spedizione (ad eccezione dei costi supplementari derivanti dalla tua eventuale scelta di un tipo di spedizione diverso dal tipo meno costoso di consegna standard da noi offerto).
Potremo effettuare una detrazione dal rimborso per la perdita di valore dei beni forniti, qualora tale perdita sia il risultato di una manipolazione non necessaria da parte tua.
Eseguiremo il rimborso senza indebito ritardo e non oltre 14 giorni dal giorno in cui saremo informati della tua decisione di recedere dal presente contratto.
Il rimborso sarà effettuato utilizzando lo stesso mezzo di pagamento da te usato per la transazione iniziale, salvo che tu non abbia espressamente concordato altrimenti; in ogni caso, non dovrai sostenere alcun costo quale conseguenza di tale rimborso.
Possiamo trattenere il rimborso finché non avremo ricevuto i beni oppure finché non avrai fornito la prova di averli rispediti, a seconda di quale condizione si verifichi per prima.
Dovrai rispedire i beni o consegnarli a Grand Eagle Retail, Bensenville, Illinois, U.S.A., senza indebito ritardo e, in ogni caso, entro 14 giorni dal giorno in cui ci hai comunicato la tua volontà di recedere dal presente contratto. Il termine è rispettato se rispedisci i beni prima della scadenza del periodo di 14 giorni. I costi diretti della restituzione dei beni saranno a tuo carico. Sei responsabile solo della diminuzione del valore dei beni risultante da una manipolazione diversa da quella necessaria per stabilire la natura, le caratteristiche e il funzionamento dei beni stessi.
Eccezioni al diritto di recesso
Il diritto di recesso non si applica a:
- La fornitura di giornali, periodici o riviste ad eccezione dei contratti di abbonamento; e
- La fornitura di contenuto digitale non fornito su un supporto materiale (ad es. su un CD o DVD), se al momento dell'invio dell'ordine hai accettato l'inizio dell'esecuzione e hai riconosciuto che non avresti potuto recedere una volta iniziata l'esecuzione.
Condizioni di spedizione
Orders usually ship within 2 business days. All books within the US ship free of charge. Delivery is 4-14 business days anywhere in the United States.
Books ship from California and Michigan.
If your book order is heavy or oversized, we may contact you to let you know extra shipping is required.