Developer Tools & Code Intelligence · core
Software Supply-chain Health
Dependency provenance, lockfiles, SBOMs, signing, build integrity, vulnerabilities, update policy, and release attestations.
Mental model
Supply-chain security proves what entered a build and how the artifact was produced. Pin inputs, generate provenance, scan risk, and verify signatures at promotion boundaries.
How to study Software Supply-chain Health
Begin by restating the mental model in your own words, then connect it to a concrete system you have built or operated. Name the mechanism, the constraint it addresses, and the trade-off it introduces. Use SLSA Specification, USENIX Security '19 — in-toto: farm-to-table guarantees for bits and bytes, in-toto: Providing farm-to-table guarantees for bits and bytes to check details, but close the source before writing your explanation. Retrieval is the learning step; rereading is only preparation.
Next, compare Software Supply-chain Health with Coding Agent Systems, Automated Debugging & Remediation. Ask what changes in correctness, latency, resource use, operability, and failure recovery. Complete Design exercise: Software Supply-chain Health and preserve the command, input, output, and one failed attempt as evidence. Finish by explaining the idea without jargon to someone who has not studied the track.
Proof of understanding
- Explain the mechanism from first principles and identify the state it reads or changes.
- Give one situation where the concept is the right choice and one where it is not.
- Predict a realistic failure mode before running the drill, then compare the prediction with evidence.
- Connect the result to a roadmap or build artifact instead of treating the concept as isolated trivia.
Learn from primary sources
Practice and explain it back
Design exercise: Software Supply-chain Health
Dependency provenance, lockfiles, SBOMs, signing, build integrity, vulnerabilities, update policy, and release attestations. Implement designOutline() returning non-empty values for: provenance, dependencyPolicy, artifactVerification. Each value must name a concrete mechanism or decision.
Expected evidence: A design outline with provenance, dependencyPolicy, artifactVerification plus an explicit failure mode or trade-off.
Open the interactive drill →Review prompts
- An SBOM and a provenance attestation answer different questions. What are they?
Build evidence
Synthesize: Developer Tools & Code Intelligence
Build repository-aware tools that analyze, test, review, debug, and safely remediate code. Produce one working system, benchmark, or evidence-backed design that integrates the path.
- Implements or precisely models the core mechanisms from all three milestones
- Includes at least one injected failure or adversarial case and demonstrates recovery
- Reports quality, latency, resource, reliability, or usability measurements relevant to the domain
- Ships a concise architecture note explaining decisions, trade-offs, and remaining risks