Isbn: 9798171782542 - software build integrity and dependency trust: protect source code, packages, build pipelines, artifacts, and release provenance (5 risultati)

Perfeziona la tua ricerca

  • Libri (5)

  • Nuovo (5)

a

Fascia di prezzo personalizzata (EUR)

a

  • Lingua: Inglese

    Editore: Independently published, 2026

    9798171782542

    • Brossura

    Da: PBShop.store US, Wood Dale, IL, U.S.A.PBShop.store US

    Venditore con 5 stelle
    Contatta il venditore

    Condizione: Nuovo

    EUR 20,66

     Spedizione gratuita 
    Spedito in U.S.A.

    Quantità: Più di 20 disponibili

    PAP. Condizione: New. New Book. Shipped from UK. Established seller since 2000.

  • Lingua: Inglese

    Editore: WENDE, 2026

    9798171782542

    • Brossura

    Da: PBShop.store UK, Fairford, GLOS, Regno UnitoPBShop.store UK

    Venditore con 5 stelle
    Contatta il venditore

    Condizione: Nuovo

    EUR 18,73

    EUR 3,87 spedizione 
    Spedito da Regno Unito a U.S.A.

    Quantità: Più di 20 disponibili

    PAP. Condizione: New. New Book. Shipped from UK. Established seller since 2000.

  • Lingua: Inglese

    Editore: Independently Published, 2026

    9798171782542

    • Brossura
    • Print on Demand

    Da: Grand Eagle Retail, Bensenville, IL, U.S.A.Grand Eagle Retail

    Venditore con 5 stelle
    Contatta il venditore

    Condizione: Nuovo

    EUR 20,13

     Spedizione gratuita 
    Spedito in U.S.A.

    Quantità: 1 disponibile

    Paperback. Condizione: new. Paperback. You reviewed the code. You scanned the dependencies. You signed the release. But can you prove that the software running in production is the exact software your organization intended to ship?Modern applications are created through far more than source code. Repositories, package registries, open-source projects, CI runners, reusable workflows, build images, compilers, caches, cloud identities, signing systems, artifact stores, containers, and deployment controllers all influence what eventually reaches production.Every one of those systems creates a trust decision.Software Build Integrity and Dependency Trust is a practical guide to designing software delivery systems in which those decisions can be verified rather than merely assumed.Instead of treating software supply-chain security as a collection of scanners and compliance checkboxes, this book shows how to build a measurable chain of evidence from authorized change to production deployment.Inside, you'll learn how to: Protect repositories, branches, tags, maintainers, workflow files, and release pathsControl third-party components before they enter sensitive environmentsDefend against namespace confusion, malicious updates, compromised maintainers, and unsafe transitive relationshipsTreat CI/CD platforms as privileged security infrastructureSeparate untrusted validation, trusted compilation, publication, signing, promotion, and deploymentBuild reproducible, hermetic, isolated, and evidence-producing environmentsUse immutable digests to identify exactly what was tested, approved, distributed, and deployedDesign signing systems around identities and policy rather than shared long-lived secretsGenerate and use SBOMs, VEX information, attestations, and machine-readable evidenceApply SLSA concepts without turning maturity levels into meaningless badgesEnforce promotion and deployment decisions through policy as codeReplace permanent automation credentials with short-lived workload identitiesPrepare for compromised runners, malicious components, stolen signers, poisoned caches, and altered release workflowsBuild forensic evidence that allows responders to quickly determine where affected components were built and deployedScale strong controls across hundreds or thousands of repositories without creating release bureaucracyReal-world incidents involving SolarWinds, Codecov, PyTorch, and xz Utils demonstrate how different parts of the delivery chain can fail-and why no single security control is enough.The book also includes a practical maturity model, a structured learning path, a 90-day implementation playbook, a seven-layer reference architecture, a ten-question architecture review, a decision matrix, and detailed operational checklists that teams can adapt to real environments.Whether you're a software engineer, DevOps or DevSecOps professional, platform engineer, cloud engineer, security engineer, architect, SRE, engineering leader, or technology risk professional, this book will help you answer the question that increasingly matters: Why should this exact software be trusted to run?Build faster when appropriate. Verify before trust. Make evidence part of the delivery system. This item is printed on demand. Shipping may be from multiple locations in the US or from the UK, depending on stock availability. …

  • Lingua: Inglese

    Editore: Independently published, 2026

    9798171782542

    • Brossura
    • Print on Demand

    Da: California Books, Miami, FL, U.S.A.California Books

    Venditore con 5 stelle
    Contatta il venditore

    Condizione: Nuovo

    EUR 20,13

     Spedizione gratuita 
    Spedito in U.S.A.

    Quantità: Più di 20 disponibili

    Condizione: New. Print on Demand.

  • Lingua: Inglese

    Editore: Independently Published, 2026

    9798171782542

    • Brossura
    • Print on Demand

    Da: CitiRetail, Stevenage, Regno UnitoCitiRetail

    Venditore con 5 stelle
    Contatta il venditore

    Condizione: Nuovo

    EUR 23,02

    EUR 43,54 spedizione 
    Spedito da Regno Unito a U.S.A.

    Quantità: 1 disponibile

    Paperback. Condizione: new. Paperback. You reviewed the code. You scanned the dependencies. You signed the release. But can you prove that the software running in production is the exact software your organization intended to ship?Modern applications are created through far more than source code. Repositories, package registries, open-source projects, CI runners, reusable workflows, build images, compilers, caches, cloud identities, signing systems, artifact stores, containers, and deployment controllers all influence what eventually reaches production.Every one of those systems creates a trust decision.Software Build Integrity and Dependency Trust is a practical guide to designing software delivery systems in which those decisions can be verified rather than merely assumed.Instead of treating software supply-chain security as a collection of scanners and compliance checkboxes, this book shows how to build a measurable chain of evidence from authorized change to production deployment.Inside, you'll learn how to: Protect repositories, branches, tags, maintainers, workflow files, and release pathsControl third-party components before they enter sensitive environmentsDefend against namespace confusion, malicious updates, compromised maintainers, and unsafe transitive relationshipsTreat CI/CD platforms as privileged security infrastructureSeparate untrusted validation, trusted compilation, publication, signing, promotion, and deploymentBuild reproducible, hermetic, isolated, and evidence-producing environmentsUse immutable digests to identify exactly what was tested, approved, distributed, and deployedDesign signing systems around identities and policy rather than shared long-lived secretsGenerate and use SBOMs, VEX information, attestations, and machine-readable evidenceApply SLSA concepts without turning maturity levels into meaningless badgesEnforce promotion and deployment decisions through policy as codeReplace permanent automation credentials with short-lived workload identitiesPrepare for compromised runners, malicious components, stolen signers, poisoned caches, and altered release workflowsBuild forensic evidence that allows responders to quickly determine where affected components were built and deployedScale strong controls across hundreds or thousands of repositories without creating release bureaucracyReal-world incidents involving SolarWinds, Codecov, PyTorch, and xz Utils demonstrate how different parts of the delivery chain can fail-and why no single security control is enough.The book also includes a practical maturity model, a structured learning path, a 90-day implementation playbook, a seven-layer reference architecture, a ten-question architecture review, a decision matrix, and detailed operational checklists that teams can adapt to real environments.Whether you're a software engineer, DevOps or DevSecOps professional, platform engineer, cloud engineer, security engineer, architect, SRE, engineering leader, or technology risk professional, this book will help you answer the question that increasingly matters: Why should this exact software be trusted to run?Build faster when appropriate. Verify before trust. Make evidence part of the delivery system. This item is printed on demand. Shipping may be from our UK warehouse or from our Australian or US warehouses, depending on stock availability. …