Software supply chain
Defines the software supply chain concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Software supply chain pattern, Security & Supply Chain software supply chain, Software supply chain implementation
- AI prompt
Implement production-ready Software supply chain for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Software bill of materials
Defines the software bill of materials concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Software bill of materials pattern, Security & Supply Chain software bill of materials, Software bill of materials implementation
- AI prompt
Implement production-ready Software bill of materials for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
CycloneDX
Defines the cyclonedx concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- CycloneDX pattern, Security & Supply Chain cyclonedx, CycloneDX implementation
- AI prompt
Implement production-ready CycloneDX for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
SPDX
Defines the spdx concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- SPDX pattern, Security & Supply Chain spdx, SPDX implementation
- AI prompt
Implement production-ready SPDX for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Provenance
Defines the provenance concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Provenance pattern, Security & Supply Chain provenance, Provenance implementation
- AI prompt
Implement production-ready Provenance for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Build attestation
Defines the build attestation concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Build attestation pattern, Security & Supply Chain build attestation, Build attestation implementation
- AI prompt
Implement production-ready Build attestation for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Artifact attestation
Defines the artifact attestation concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Artifact attestation pattern, Security & Supply Chain artifact attestation, Artifact attestation implementation
- AI prompt
Implement production-ready Artifact attestation for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
SLSA
Defines the slsa concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- SLSA pattern, Security & Supply Chain slsa, SLSA implementation
- AI prompt
Implement production-ready SLSA for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Reproducible build
Defines the reproducible build concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Reproducible build pattern, Security & Supply Chain reproducible build, Reproducible build implementation
- AI prompt
Implement production-ready Reproducible build for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Hermetic build
Defines the hermetic build concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Hermetic build pattern, Security & Supply Chain hermetic build, Hermetic build implementation
- AI prompt
Implement production-ready Hermetic build for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Trusted builder
Defines the trusted builder concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Trusted builder pattern, Security & Supply Chain trusted builder, Trusted builder implementation
- AI prompt
Implement production-ready Trusted builder for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Ephemeral builder
Defines the ephemeral builder concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Ephemeral builder pattern, Security & Supply Chain ephemeral builder, Ephemeral builder implementation
- AI prompt
Implement production-ready Ephemeral builder for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Artifact signing
Defines the artifact signing concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Artifact signing pattern, Security & Supply Chain artifact signing, Artifact signing implementation
- AI prompt
Implement production-ready Artifact signing for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Image signing
Defines the image signing concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Image signing pattern, Security & Supply Chain image signing, Image signing implementation
- AI prompt
Implement production-ready Image signing for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Signature verification
Defines the signature verification concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Signature verification pattern, Security & Supply Chain signature verification, Signature verification implementation
- AI prompt
Implement production-ready Signature verification for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Keyless signing
Defines the keyless signing concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Keyless signing pattern, Security & Supply Chain keyless signing, Keyless signing implementation
- AI prompt
Implement production-ready Keyless signing for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Transparency log
Defines the transparency log concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Transparency log pattern, Security & Supply Chain transparency log, Transparency log implementation
- AI prompt
Implement production-ready Transparency log for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Admission policy
Defines the admission policy concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Admission policy pattern, Security & Supply Chain admission policy, Admission policy implementation
- AI prompt
Implement production-ready Admission policy for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Artifact allowlist
Defines the artifact allowlist concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Artifact allowlist pattern, Security & Supply Chain artifact allowlist, Artifact allowlist implementation
- AI prompt
Implement production-ready Artifact allowlist for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Registry policy
Defines the registry policy concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Registry policy pattern, Security & Supply Chain registry policy, Registry policy implementation
- AI prompt
Implement production-ready Registry policy for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Dependency confusion
Defines the dependency confusion concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Dependency confusion pattern, Security & Supply Chain dependency confusion, Dependency confusion implementation
- AI prompt
Implement production-ready Dependency confusion for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Typosquatting
Defines the typosquatting concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Typosquatting pattern, Security & Supply Chain typosquatting, Typosquatting implementation
- AI prompt
Implement production-ready Typosquatting for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Package takeover
Defines the package takeover concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Package takeover pattern, Security & Supply Chain package takeover, Package takeover implementation
- AI prompt
Implement production-ready Package takeover for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Build-script risk
Defines the build-script risk concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Build-script risk pattern, Security & Supply Chain build-script risk, Build-script risk implementation
- AI prompt
Implement production-ready Build-script risk for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Compromised runner
Defines the compromised runner concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Compromised runner pattern, Security & Supply Chain compromised runner, Compromised runner implementation
- AI prompt
Implement production-ready Compromised runner for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Branch protection
Defines the branch protection concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Branch protection pattern, Security & Supply Chain branch protection, Branch protection implementation
- AI prompt
Implement production-ready Branch protection for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Required review
Defines the required review concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Required review pattern, Security & Supply Chain required review, Required review implementation
- AI prompt
Implement production-ready Required review for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Protected environment
Defines the protected environment concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Protected environment pattern, Security & Supply Chain protected environment, Protected environment implementation
- AI prompt
Implement production-ready Protected environment for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Least-privilege pipeline
Defines the least-privilege pipeline concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Least-privilege pipeline pattern, Security & Supply Chain least-privilege pipeline, Least-privilege pipeline implementation
- AI prompt
Implement production-ready Least-privilege pipeline for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
OIDC workload identity
Defines the oidc workload identity concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- OIDC workload identity pattern, Security & Supply Chain oidc workload identity, OIDC workload identity implementation
- AI prompt
Implement production-ready OIDC workload identity for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Short-lived credential
Defines the short-lived credential concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Short-lived credential pattern, Security & Supply Chain short-lived credential, Short-lived credential implementation
- AI prompt
Implement production-ready Short-lived credential for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Runtime security
Defines the runtime security concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Runtime security pattern, Security & Supply Chain runtime security, Runtime security implementation
- AI prompt
Implement production-ready Runtime security for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Container sandbox
Defines the container sandbox concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Container sandbox pattern, Security & Supply Chain container sandbox, Container sandbox implementation
- AI prompt
Implement production-ready Container sandbox for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Pod security
Defines the pod security concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Pod security pattern, Security & Supply Chain pod security, Pod security implementation
- AI prompt
Implement production-ready Pod security for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Network policy
Defines the network policy concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Network policy pattern, Security & Supply Chain network policy, Network policy implementation
- AI prompt
Implement production-ready Network policy for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Egress control
Defines the egress control concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Egress control pattern, Security & Supply Chain egress control, Egress control implementation
- AI prompt
Implement production-ready Egress control for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Runtime detection
Defines the runtime detection concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Runtime detection pattern, Security & Supply Chain runtime detection, Runtime detection implementation
- AI prompt
Implement production-ready Runtime detection for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
File-integrity monitoring
Defines the file-integrity monitoring concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- File-integrity monitoring pattern, Security & Supply Chain file-integrity monitoring, File-integrity monitoring implementation
- AI prompt
Implement production-ready File-integrity monitoring for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Security audit
Defines the security audit concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Security audit pattern, Security & Supply Chain security audit, Security audit implementation
- AI prompt
Implement production-ready Security audit for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Compliance evidence
Defines the compliance evidence concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Compliance evidence pattern, Security & Supply Chain compliance evidence, Compliance evidence implementation
- AI prompt
Implement production-ready Compliance evidence for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Exception process
Defines the exception process concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Exception process pattern, Security & Supply Chain exception process, Exception process implementation
- AI prompt
Implement production-ready Exception process for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Break-glass access
Defines the break-glass access concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Break-glass access pattern, Security & Supply Chain break-glass access, Break-glass access implementation
- AI prompt
Implement production-ready Break-glass access for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.
Security incident
Defines the security incident concept used in security & supply chain, including its responsibilities, boundaries, failure modes, and operational considerations.
- Also known as
- Security incident pattern, Security & Supply Chain security incident, Security incident implementation
- AI prompt
Implement production-ready Security incident for a devops system. Define its contract, configuration, security boundaries, lifecycle, failure and recovery behavior, observability, performance limits, automated tests, rollout plan, and framework-neutral examples.