Software Supply Chain Security: Curation, Policies, and Catalog Management (JFTC 506)
Designed for DevSecOps and Security Champions, this course uses JFrog Curation to block malicious packages at the source. You will configure risk policies, manage waivers, and leverage dedicated resources and tools to develop a comprehensive execution plan.
Course Level: Foundational
Requirements:
Understanding of the Software Development Lifecycle.
Basic knowledge of JFrog Artifactory.
Prerequisites:
Completion of JFrog Platform Essentials is recommended.
Familiarity with package managers (e.g., npm, Maven, Python).
Topics Covered:
Shift-Left Methodology: Integrating security practices early in the development lifecycle (pre-build).
Risk Conditions: Defining Security (CVE/Malicious), Operational (Age/Version), and Legal (License) conditions.
JFrog Catalog: Using the catalog as a single source of truth for package metadata and risk assessment.
Administration: Managing audit logs, notifications, and global curation settings.
Execution Plan: A phased approach including initiation, configuration, dry run, and enforcement.
How it works:
These 3 hour live, instructor-led sessions provide an interactive learning environment featuring real-time Q&A and hands-on labs to practice practical exercises.
*Incase a refund is require, please contact training@jfrog.com