Software Build Integrity and Dependency Trust (Paperback)
Rion Frost
Sold by Grand Eagle Retail, Bensenville, IL, U.S.A.
AbeBooks Seller since 12 October 2005
New - Soft cover
Condition: New
Ships within U.S.A.
Quantity: 1 available
Add to basketSold by Grand Eagle Retail, Bensenville, IL, U.S.A.
AbeBooks Seller since 12 October 2005
Condition: New
Quantity: 1 available
Add to basketPaperback. You reviewed the code. You scanned the dependencies. You signed the release. But can you prove that the software running in production is the exact software your organization intended to ship?Modern applications are created through far more than source code. Repositories, package registries, open-source projects, CI runners, reusable workflows, build images, compilers, caches, cloud identities, signing systems, artifact stores, containers, and deployment controllers all influence what eventually reaches production.Every one of those systems creates a trust decision.Software Build Integrity and Dependency Trust is a practical guide to designing software delivery systems in which those decisions can be verified rather than merely assumed.Instead of treating software supply-chain security as a collection of scanners and compliance checkboxes, this book shows how to build a measurable chain of evidence from authorized change to production deployment.Inside, you'll learn how to: Protect repositories, branches, tags, maintainers, workflow files, and release pathsControl third-party components before they enter sensitive environmentsDefend against namespace confusion, malicious updates, compromised maintainers, and unsafe transitive relationshipsTreat CI/CD platforms as privileged security infrastructureSeparate untrusted validation, trusted compilation, publication, signing, promotion, and deploymentBuild reproducible, hermetic, isolated, and evidence-producing environmentsUse immutable digests to identify exactly what was tested, approved, distributed, and deployedDesign signing systems around identities and policy rather than shared long-lived secretsGenerate and use SBOMs, VEX information, attestations, and machine-readable evidenceApply SLSA concepts without turning maturity levels into meaningless badgesEnforce promotion and deployment decisions through policy as codeReplace permanent automation credentials with short-lived workload identitiesPrepare for compromised runners, malicious components, stolen signers, poisoned caches, and altered release workflowsBuild forensic evidence that allows responders to quickly determine where affected components were built and deployedScale strong controls across hundreds or thousands of repositories without creating release bureaucracyReal-world incidents involving SolarWinds, Codecov, PyTorch, and xz Utils demonstrate how different parts of the delivery chain can fail-and why no single security control is enough.The book also includes a practical maturity model, a structured learning path, a 90-day implementation playbook, a seven-layer reference architecture, a ten-question architecture review, a decision matrix, and detailed operational checklists that teams can adapt to real environments.Whether you're a software engineer, DevOps or DevSecOps professional, platform engineer, cloud engineer, security engineer, architect, SRE, engineering leader, or technology risk professional, this book will help you answer the question that increasingly matters: Why should this exact software be trusted to run?Build faster when appropriate. Verify before trust. Make evidence part of the delivery system. This item is printed on demand. Shipping may be from multiple locations in the US or from the UK, depending on stock availability.
Seller Inventory # 9798171782542
You reviewed the code. You scanned the dependencies. You signed the release. But can you prove that the software running in production is the exact software your organization intended to ship?
Modern applications are created through far more than source code. Repositories, package registries, open-source projects, CI runners, reusable workflows, build images, compilers, caches, cloud identities, signing systems, artifact stores, containers, and deployment controllers all influence what eventually reaches production.
Every one of those systems creates a trust decision.
Software Build Integrity and Dependency Trust is a practical guide to designing software delivery systems in which those decisions can be verified rather than merely assumed.
Instead of treating software supply-chain security as a collection of scanners and compliance checkboxes, this book shows how to build a measurable chain of evidence from authorized change to production deployment.
Inside, you'll learn how to:
Real-world incidents involving SolarWinds, Codecov, PyTorch, and xz Utils demonstrate how different parts of the delivery chain can fail—and why no single security control is enough.
The book also includes a practical maturity model, a structured learning path, a 90-day implementation playbook, a seven-layer reference architecture, a ten-question architecture review, a decision matrix, and detailed operational checklists that teams can adapt to real environments.
Whether you're a software engineer, DevOps or DevSecOps professional, platform engineer, cloud engineer, security engineer, architect, SRE, engineering leader, or technology risk professional, this book will help you answer the question that increasingly matters:
Why should this exact software be trusted to run?
Build faster when appropriate. Verify before trust. Make evidence part of the delivery system.
"About this title" may belong to another edition of this title.
We guarantee the condition of every book as it¿s described on the Abebooks web sites. If you¿ve changed
your mind about a book that you¿ve ordered, please use the Ask bookseller a question link to contact us
and we¿ll respond within 2 business days.
Books ship from California and Michigan.
If you are a consumer you can withdraw from the contract in accordance with the following. Consumer means any natural person who is acting for purposes which are outside his trade, business, craft or profession.
Information regarding the right of withdrawal
Statutory right to withdraw
You have the right to withdraw from this contract within 14 days without giving any reason.
The withdrawal period will expire after 14 days from the day on which you acquire, or a third party other than the carrier and indicated by you acquires, physical possession of the last good or the last lot or piece.
To exercise the right of withdrawal, electronically fill in and submit a clear statement on our website, under "My Purchases" in "My Account". We will communicate to you an acknowledgement of receipt of such a withdrawal on a durable medium (e.g. by e-mail) without delay.
To meet the withdrawal deadline, it is sufficient for you to send your communication concerning your exercise of the right of withdrawal before the withdrawal period has expired.
Effects of withdrawal
If you withdraw from this contract, we will reimburse to you all payments received from you, including the costs of delivery (except for the supplementary costs arising if you chose a type of delivery other than the least expensive type of standard delivery offered by us).
We may make a deduction from the reimbursement for loss in value of any goods supplied, if the loss is the result of unnecessary handling by you.
We will make the reimbursement without undue delay, and not later than 14 days after the day on which we are informed about your decision to withdraw from this contract.
We will make the reimbursement using the same means of payment as you used for the initial transaction, unless you have expressly agreed otherwise; in any event, you will not incur any fees as a result of such reimbursement.
We may withhold reimbursement until we have received the goods back, or you have supplied evidence of having sent back the goods, whichever is the earliest.
You shall send back the goods or hand them over to Grand Eagle Retail, Bensenville, Illinois, U.S.A., without undue delay and in any event not later than 14 days from the day on which you communicate your withdrawal from this contract to us. The deadline is met if you send back the goods before the period of 14 days has expired. You will have to bear the direct cost of returning the goods. You are only liable for any diminished value of the goods resulting from the handling other than what is necessary to establish the nature, characteristics and functioning of the goods.
Exceptions to the right of withdrawal
The right of withdrawal does not apply to:
Orders usually ship within 2 business days. All books within the US ship free of charge. Delivery is 4-14 business days anywhere in the United States.
Books ship from California and Michigan.
If your book order is heavy or oversized, we may contact you to let you know extra shipping is required.
| Order quantity | 6 to 16 business days | 6 to 14 business days |
|---|---|---|
| First item | £ 0.00 | £ 0.00 |
Delivery times are set by sellers and vary by carrier and location. Orders passing through Customs may face delays and buyers are responsible for any associated duties or fees. Sellers may contact you regarding additional charges to cover any increased costs to ship your items.