Project challenges / verified progress
Beacon: ship it without fear

The engineering notebook

Prove what you ship

How does CI earn trust without storing long-lived secrets?

Loading statusStage 3 of 9

  • Workspace not ready
  • Agent not ready
Focus25:00
A small focus ritual

0 focus sessions completed. Every fourth session offers a longer break. Start each phase when you are ready.

Study time never unlocks verified lesson progress.

Loading...

Loading verified progress...

Loading GitHub account...
Protect the artifact

Step 01 of 06

Learn the concept

A pipeline that builds malware very reliably is still a good pipeline, technically. Supply-chain gates ask a harder question: what exactly did we build, what was inside it, who vouched for it, and can an attacker forge that story?

LAYERS OF ARTIFACT TRUSTPolicy resultcritical CVEs failgateProvenancebuilder identitySLSASignaturekeyless CosignOIDCSBOMpackages namedSPDXPinned actionscode is fixedSHA
Each layer narrows a different attack. A signed artifact with no SBOM is opaque. A clean scan with an unpinned action may only prove that today's tag was friendly.
Step 01

The ideas this is made of

An SBOM names the ingredients

A Software Bill of Materials lists packages, versions and relationships. It is not a vulnerability report. It is the inventory the report depends on. During a new CVE, teams with usable SBOMs can answer whether they contain the package.

Keyless signing uses identity instead of a stored key

Cosign can sign with GitHub's OIDC token, producing a certificate bound to repository, workflow and commit. No long-lived signing key sits in secrets. That removes a leak class, but makes workflow permissions important.

Pinned actions stop tags from becoming invisible supply chain

uses: owner/action@v1 follows a tag, and tags can move. A full commit SHA names immutable code. The trade-off is maintenance: you need tooling or a calendar to update pins before they become fossils.

`pull_request_target` is a loaded footgun

pull_request_target runs in the base repository context and may access secrets and write tokens. If it checks out and runs code from an untrusted fork, the fork can steal that power. Use it only for metadata operations.

A signed bakery batch
batch: sourdough-2026-10-05
ingredients: flour@lot-813, salt@lot-044
baker: night-shift-2
signed-by: bakery identity

The bread is not safer because the receipt exists. The receipt lets a buyer reject a batch whose ingredients, builder or signature do not match policy.

Secrets and identity in CI

MechanismLifetimeBest useMain risk

Repository secret

Until rotated

Legacy API tokens

Replay after leak

OIDC token

Minutes

Cosign, federation

Overbroad permission

GITHUB_TOKEN

One run

GitHub API

Write scope carelessness

Commit SHA pin

Immutable

Trusted actions

Update process needed

What these are called on the job

  • SBOM — Machine-readable inventory of packages and files in an artifact.

  • OIDC — Short-lived identity token issued to a workflow run.

  • SLSA — A framework for build integrity and provenance levels.

  • Critical CVE — A vulnerability severe enough that policy normally blocks release.