Guide
Premium
Intermediate
Real Projects

Software Supply Chain Security: Lockfiles, Release Cooldowns, OIDC Trusted Publishing and Sigstore Signatures

A practical guide to closing the five doors a supply chain attack walks through: strict lockfile installs, blocking the postinstall scripts that propagated the Shai-Hulud worm, release cooldowns (min-release-age, minimumReleaseAge, npmMinimalAgeGate) coordinated with Dependabot and Renovate, pinning GitHub Actions to full SHAs with pinact, least-privilege permissions and the pull_request_target trap, token-free publishing with OIDC Trusted Publishing on PyPI and npm, SLSA build provenance and SBOM attestations signed with Sigstore, and admission-time verification with cosign and Kyverno that checks identity, not just signature. Includes a CI-ready lockfile audit script, complete workflows, the eight mistakes that undo all the work, an impact-ordered rollout plan, a production checklist and an FAQ. Expanded edition: the same model applied to Python (wheels vs sdists, --require-hashes), Go (sum.golang.org and the GOPRIVATE=* trap), Rust (build.rs, cargo-vet, cargo-deny), Gradle (verification-metadata.xml) and digest-pinned base images; dependency confusion, typosquatting and slopsquatting with a CI-ready pull request check; Sigstore from the inside (Fulcio, Rekor, and why you verify identity rather than a key); operational SBOMs with CycloneDX, Dependency-Track and VEX; a first-24-hours incident runbook; and governing this at scale with OpenSSF Scorecard, SLSA levels and reusable workflows.

42 minutes read
Josué Puig
1 views

Verificando acceso...

Loading comments...

Related Resources

Guía
PREMIUM

asyncio in Production: Never Block the Event Loop — TaskGroups, Cancellation and Bounded Concurrency

A practical asyncio guide for Python services in production: why blocking the event loop degrades the whole process without raising a single exception, how to catch it by measuring loop lag and with Python 3.14 introspection, structured concurrency with TaskGroup and handling ExceptionGroup via except*, the task the garbage collector makes vanish, timeouts with a deadline budget propagated across services, correct cancellation with cleanup and shield, bounded concurrency with semaphores and backpressured queues, synchronization primitives, and what changes with eager tasks, python -m asyncio pstree and free-threading. With production-ready code and a deployment checklist.

Guía
PREMIUM

Cache-Aside in Production: TTLs, Invalidation, and How to Prevent Cache Stampedes

The complete guide to the cache-aside pattern with Redis: jittered TTLs, correct invalidation, and the three defenses against cache stampedes (distributed lock, single-flight, and XFetch). Expanded with stale-while-revalidate, fail-open and circuit breakers, two-tier caching with RESP3 invalidation, delayed double delete and CDC, hot keys, eviction and memory management, observability with Prometheus, testing, choosing an engine (Redis, Valkey, Memcached), and a complete TypeScript implementation. With production-ready code in Python and TypeScript.

Guía
PREMIUM

Circuit Breakers: How to Prevent Cascading Failures in Distributed Systems

Learn to implement the circuit breaker pattern so a failing dependency never drags down your whole system: the three states (closed, open, half-open), sliding failure windows, limited probes to avoid thundering herds, robust fallbacks, and how to combine it with timeouts, retries, and bulkheads. Includes distributed state in Redis, observability with Prometheus, pytest testing, circuit breaking in Envoy/Istio, a full case study, and production-ready code in Python and TypeScript.