Trusted Software Supply Chain (TSSC) Labs Overview

Overview

These labs cover Trusted Software Supply Chain (TSSC) capabilities on OpenShift: Trusted Artifact Signer (container and git signing) and Trusted Profile Analyzer (SBOM analysis).

Use this track after (or alongside) the role path that owns supply-chain controls—especially DevSecOps and Security Architect. Related framework labs include 201-05 and 301-06.

Audience and prerequisites:

  • OpenShift cluster with TSSC components available in this environment

  • Familiarity with container images, git workflows, and basic CLI on the bastion

  • Credentials and console links are on the home page

TSSC Labs Index

Lab Title Focus

TSSC-00

Trusted Artifact Signer — Container Signing

Sign and verify container images with TAS

TSSC-01

Git Commit Signing with Trusted Artifact Signer

Sign and verify git commits

TSSC-02

Trusted Profile Analyzer

SBOM analysis and vulnerability insights