Supply-chain Levels for Software Artifacts
-
Updated
Nov 6, 2024 - Shell
Supply-chain Levels for Software Artifacts
Deploy Anchore Enterprise in an environment of your choice. Then follow through a series of labs that showcase how you can improve security across your software supply chain.
Bitbucket pipe to generate a CycloneDX sBOM for node/npm projects
git hooks to prevent committing vulnerable dependencies
A simple CircleCI orb used to install Cosign and sign container images
A simple CircleCI orb used to install Syft and produce SBOMs for container images
Bitbucket pipe to generate a CycloneDX sBOM for Java, Go, Python & Node projects
Add a description, image, and links to the supply-chain-security topic page so that developers can more easily learn about it.
To associate your repository with the supply-chain-security topic, visit your repo's landing page and select "manage topics."