Topics

Software Supply Chain Security · 3:40

Listen on 93

Lyrics

[Verse 1]
When maintainers fall to social schemes
And repositories aren't what they seem
Bad actors plant their malicious code
In packages we trust along the road
Dependency confusion leads us astray
While typosquatters wait for our mistake

[Chorus]
Sign and verify, hash and pin it tight
SLSA levels guide us through the night
Build provenance tells the story true
Supply chain armor protects me and you
Attestations capture every step
Security boundaries we must prep

[Verse 2]
Registry compromise spreads the pain
CI systems hacked, trust goes down the drain
Signing keys stolen in the dark of night
Everything we built no longer feels right
But Sigstore and cosign light the way
With cryptographic proof to save the day

[Chorus]
Sign and verify, hash and pin it tight
SLSA levels guide us through the night
Build provenance tells the story true
Supply chain armor protects me and you
Attestations capture every step
Security boundaries we must prep

[Bridge]
Level zero means we're flying blind
Level one through four, maturity refined
Environment capture shows the scene
Where our artifacts have really been
From source to build to final deploy
These controls are tools we must employ

[Verse 3]
Hash pinning locks down what we expect
Signature verification keeps threats in check
Build environment captured in detail
Provenance records tell the faithful tale
When dependencies try to deceive
These attestations make us believe

[Chorus]
Sign and verify, hash and pin it tight
SLSA levels guide us through the night
Build provenance tells the story true
Supply chain armor protects me and you
Attestations capture every step
Security boundaries we must prep

[Outro]
In this modern stack we're building on
Supply chain threats will come and go
But with these controls we'll carry on
Trust through verification we now know

← Exercises | Exercises →