[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"me":3,"catalog:en:security\u002Fds-software-supply-chain-pipeline":4,"config":232},null,{"field_key":5,"field_name":6,"seniority":7,"topic_key":8,"topic_name":9,"spec_key":7,"spec_name":7,"locale":10,"cell_total":11,"field_total":12,"seniorities":13,"topics":17,"specs":130,"samples":147},"security","Security","","ds-software-supply-chain-pipeline","Ds Software Supply Chain Pipeline","en",75,2850,[14,15,16],"junior","mid","senior",[18,21,24,27,30,33,36,39,42,45,48,51,54,57,60,63,66,69,72,75,78,81,84,87,88,91,94,97,100,103,106,109,112,115,118,121,124,127],{"key":19,"name":20,"count":11},"as-access-control-idor","As Access Control Idor",{"key":22,"name":23,"count":11},"as-api-security","As Api Security",{"key":25,"name":26,"count":11},"as-authentication-session","As Authentication Session",{"key":28,"name":29,"count":11},"as-crypto-implementation-pitfalls","As Crypto Implementation Pitfalls",{"key":31,"name":32,"count":11},"as-injection-input-validation","As Injection Input Validation",{"key":34,"name":35,"count":11},"as-secure-sdlc-sast-dast","As Secure Sdlc Sast Dast",{"key":37,"name":38,"count":11},"bt-crisis-communication-management","Bt Crisis Communication Management",{"key":40,"name":41,"count":11},"bt-detection-engineering-tuning","Bt Detection Engineering Tuning",{"key":43,"name":44,"count":11},"bt-digital-forensics-fundamentals","Bt Digital Forensics Fundamentals",{"key":46,"name":47,"count":11},"bt-incident-triage-classification","Bt Incident Triage Classification",{"key":49,"name":50,"count":11},"bt-ir-playbook-execution","Bt Ir Playbook Execution",{"key":52,"name":53,"count":11},"bt-threat-intelligence-application","Bt Threat Intelligence Application",{"key":55,"name":56,"count":11},"cse-container-workload-security","Cse Container Workload Security",{"key":58,"name":59,"count":11},"cse-cspm-misconfiguration","Cse Cspm Misconfiguration",{"key":61,"name":62,"count":11},"cse-data-protection-governance","Cse Data Protection Governance",{"key":64,"name":65,"count":11},"cse-detection-incident-response","Cse Detection Incident Response",{"key":67,"name":68,"count":11},"cse-iam-privilege-escalation","Cse Iam Privilege Escalation",{"key":70,"name":71,"count":11},"cse-network-perimeter-zero-trust","Cse Network Perimeter Zero Trust",{"key":73,"name":74,"count":11},"ds-iac-policy-as-code","Ds Iac Policy As Code",{"key":76,"name":77,"count":11},"ds-pipeline-security-gates","Ds Pipeline Security Gates",{"key":79,"name":80,"count":11},"ds-secrets-pipeline-management","Ds Secrets Pipeline Management",{"key":82,"name":83,"count":11},"ds-security-metrics-blameless-culture","Ds Security Metrics Blameless Culture",{"key":85,"name":86,"count":11},"ds-shift-left-security-culture","Ds Shift Left Security Culture",{"key":8,"name":9,"count":11},{"key":89,"name":90,"count":11},"pt-legal-ethical-boundaries","Pt Legal Ethical Boundaries",{"key":92,"name":93,"count":11},"pt-methodology-phases","Pt Methodology Phases",{"key":95,"name":96,"count":11},"pt-red-team-engagement-management","Pt Red Team Engagement Management",{"key":98,"name":99,"count":11},"pt-reporting-remediation-prioritization","Pt Reporting Remediation Prioritization",{"key":101,"name":102,"count":11},"pt-scoping-rules-of-engagement","Pt Scoping Rules Of Engagement",{"key":104,"name":105,"count":11},"pt-vulnerability-assessment-vs-pentest","Pt Vulnerability Assessment Vs Pentest",{"key":107,"name":108,"count":11},"security-authn-authz","Security Authn Authz",{"key":110,"name":111,"count":11},"security-cloud-infra-security","Security Cloud Infra Security",{"key":113,"name":114,"count":11},"security-compliance-risk","Security Compliance Risk",{"key":116,"name":117,"count":11},"security-cryptography-basics","Security Cryptography Basics",{"key":119,"name":120,"count":11},"security-incident-response","Security Incident Response",{"key":122,"name":123,"count":11},"security-network-security","Security Network Security",{"key":125,"name":126,"count":11},"security-secure-sdlc","Security Secure Sdlc",{"key":128,"name":129,"count":11},"security-web-vulnerabilities","Security Web Vulnerabilities",[131,135,138,141,144],{"key":132,"name":133,"count":134},"appsec","AppSec",450,{"key":136,"name":137,"count":134},"blue-team-incident","Blue Team \u002F Incident",{"key":139,"name":140,"count":134},"cloud-security","Cloud Security",{"key":142,"name":143,"count":134},"devsecops","DevSecOps",{"key":145,"name":146,"count":134},"offensive-pentest","Offensive \u002F Pentest",[148,166,179,193,206,219],{"id":149,"topic":9,"difficulty":150,"body":151,"options":152,"correct_key":154,"explanation":165},"019fab8f-ce5d-7206-8b81-4f1990350f49",1,"What is the main goal of \"software supply chain security\" in the context of a build pipeline?",[153,156,159,162],{"key":154,"text":155},"a","Ensuring the integrity of the process that turns source into a deployable artifact.",{"key":157,"text":158},"b","Ensuring the production database has enough replicas to survive a regional outage",{"key":160,"text":161},"c","Ensuring customer support tickets are answered within a fixed SLA window",{"key":163,"text":164},"d","Ensuring the frontend framework is updated to the newest major version every quarter","Software supply chain security in the pipeline sense is about trusting the process that produces an artifact: who touched the source, what tools built it, and whether the resulting binary matches what was intended, rather than about runtime infrastructure or support processes.",{"id":167,"topic":9,"difficulty":150,"body":168,"options":169,"correct_key":163,"explanation":178},"019fab8f-ce5d-7c9a-9e7d-76038c2ab457","What does \"build provenance\" refer to in a CI\u002FCD pipeline?",[170,172,174,176],{"key":154,"text":171},"The number of unit tests that passed during the most recent test run",{"key":157,"text":173},"The list of open issues currently assigned to the release branch",{"key":160,"text":175},"The uptime percentage of the artifact registry over the last month",{"key":163,"text":177},"A verifiable record of which commit and system produced the artifact.","Build provenance is metadata that answers \"where did this artifact come from and how was it made\" — source commit, builder identity, build steps — so downstream consumers can verify the artifact traces back to a trusted, expected build rather than an unknown origin.",{"id":180,"topic":9,"difficulty":181,"body":182,"options":183,"correct_key":157,"explanation":192},"019fab8f-ce5e-77d1-841b-68a9ef5b4a0b",2,"SLSA (Supply-chain Levels for Software Artifacts) defines a set of increasing maturity levels. What is the general idea behind these levels?",[184,186,188,190],{"key":154,"text":185},"Each level corresponds to a different programming language the pipeline is allowed to compile",{"key":157,"text":187},"Each level adds stronger isolation, provenance, and tamper-resistance requirements.",{"key":160,"text":189},"Each level represents a discount tier offered by a specific CI\u002FCD vendor",{"key":163,"text":191},"Each level measures how many developers are allowed to push directly to the main branch","SLSA levels progressively raise the bar: higher levels require things like a hosted, auditable build platform, isolated build environments, and verifiable non-forgeable provenance, giving consumers a common vocabulary for how trustworthy a given build process is.",{"id":194,"topic":9,"difficulty":181,"body":195,"options":196,"correct_key":154,"explanation":205},"019fab8f-ce5f-72f3-bcd6-7a8437d1c582","What is the purpose of digitally signing a build artifact (such as a container image or binary) before publishing it to a registry?",[197,199,201,203],{"key":154,"text":198},"To let consumers verify the publisher and integrity of the artifact.",{"key":157,"text":200},"To automatically fix any known CVEs present in the artifact's dependencies",{"key":160,"text":202},"To translate the artifact's documentation into multiple languages",{"key":163,"text":204},"To make the artifact smaller so it downloads faster from the registry","A signature over an artifact, verified against the publisher's key, lets anyone pulling that artifact confirm both authenticity (it really came from that publisher) and integrity (nothing changed after signing), which is central to trusting artifacts pulled from a shared registry.",{"id":207,"topic":9,"difficulty":150,"body":208,"options":209,"correct_key":157,"explanation":218},"019fab8f-ce60-70fb-b597-961ee429aa82","In supply chain security tooling such as Sigstore, what is an \"attestation\"?",[210,212,214,216],{"key":154,"text":211},"A performance benchmark comparing two container runtimes",{"key":157,"text":213},"A signed statement asserting a fact about how an artifact was built.",{"key":160,"text":215},"A firewall rule that blocks outbound traffic from the build agent",{"key":163,"text":217},"A ticket filed automatically when a build takes longer than expected","An attestation is a signed metadata statement bound to an artifact, for example \"this image was produced by build X from commit Y and passed test suite Z.\" Consumers or policy engines can later verify the signature and check the claims before trusting or deploying the artifact.",{"id":220,"topic":9,"difficulty":181,"body":221,"options":222,"correct_key":160,"explanation":231},"019fab8f-ce61-72a5-8865-262797ff83dd","What is the core idea behind a \"reproducible build\"?",[223,225,227,229],{"key":154,"text":224},"The build must run on at least three different cloud providers before it is trusted",{"key":157,"text":226},"The build pipeline must be rewritten from scratch every six months",{"key":160,"text":228},"Building the same source under the same conditions yields an identical artifact.",{"key":163,"text":230},"The build must complete in under sixty seconds regardless of project size","Reproducibility means independent parties can rebuild from the same source and inputs and get an identical artifact, byte for byte. This lets anyone verify that a published artifact genuinely corresponds to the source it claims to be built from, without having to trust the original builder blindly.",{"fields":233,"seniorities":407,"interview_shapes":408,"locales":413,"oauth":415,"question_count":418,"coach_enabled":419,"jd_match_enabled":419},[234,259,279,296,320,333,352,371,381,388,394,401],{"key":235,"name_tr":236,"name_en":236,"sort":150,"specializations":237},"backend","Backend",[238,241,244,247,250,253,256],{"key":239,"name":240,"field":235},"general","Genel",{"key":242,"name":243,"field":235},"go","Go",{"key":245,"name":246,"field":235},"python","Python",{"key":248,"name":249,"field":235},"java","Java",{"key":251,"name":252,"field":235},"csharp","C#\u002F.NET",{"key":254,"name":255,"field":235},"nodejs","Node.js",{"key":257,"name":258,"field":235},"php","PHP",{"key":260,"name_tr":261,"name_en":261,"sort":181,"specializations":262},"frontend","Frontend",[263,264,267,270,273,276],{"key":239,"name":240,"field":260},{"key":265,"name":266,"field":260},"javascript","JavaScript",{"key":268,"name":269,"field":260},"typescript","TypeScript",{"key":271,"name":272,"field":260},"react","React",{"key":274,"name":275,"field":260},"vue","Vue",{"key":277,"name":278,"field":260},"angular","Angular",{"key":280,"name_tr":281,"name_en":281,"sort":282,"specializations":283},"fullstack","Fullstack",3,[284,285,286,287,288,289,290,291,292,293,294,295],{"key":239,"name":240,"field":280},{"key":242,"name":243,"field":235},{"key":245,"name":246,"field":235},{"key":248,"name":249,"field":235},{"key":251,"name":252,"field":235},{"key":254,"name":255,"field":235},{"key":257,"name":258,"field":235},{"key":265,"name":266,"field":260},{"key":268,"name":269,"field":260},{"key":271,"name":272,"field":260},{"key":274,"name":275,"field":260},{"key":277,"name":278,"field":260},{"key":297,"name_tr":298,"name_en":298,"sort":299,"specializations":300},"devops-cloud","DevOps \u002F Cloud",4,[301,302,305,308,311,314,317],{"key":239,"name":240,"field":297},{"key":303,"name":304,"field":297},"aws","AWS",{"key":306,"name":307,"field":297},"gcp","GCP",{"key":309,"name":310,"field":297},"azure","Azure",{"key":312,"name":313,"field":297},"kubernetes","Kubernetes",{"key":315,"name":316,"field":297},"terraform","Terraform",{"key":318,"name":319,"field":297},"linux","Linux",{"key":321,"name_tr":322,"name_en":322,"sort":323,"specializations":324},"ai-engineer","AI Engineer",5,[325,326,327,330],{"key":239,"name":240,"field":321},{"key":245,"name":246,"field":321},{"key":328,"name":329,"field":321},"llm-rag","LLM\u002FRAG",{"key":331,"name":332,"field":321},"mlops","MLOps",{"key":334,"name_tr":335,"name_en":336,"sort":337,"specializations":338},"database","Veritabanı","Database",6,[339,340,343,346,349],{"key":239,"name":240,"field":334},{"key":341,"name":342,"field":334},"postgresql","PostgreSQL",{"key":344,"name":345,"field":334},"mysql","MySQL",{"key":347,"name":348,"field":334},"mongodb","MongoDB",{"key":350,"name":351,"field":334},"redis","Redis",{"key":353,"name_tr":354,"name_en":355,"sort":356,"specializations":357},"mobile","Mobil","Mobile",7,[358,359,362,365,368],{"key":239,"name":240,"field":353},{"key":360,"name":361,"field":353},"ios-swift","iOS (Swift)",{"key":363,"name":364,"field":353},"android-kotlin","Android (Kotlin)",{"key":366,"name":367,"field":353},"flutter","Flutter",{"key":369,"name":370,"field":353},"react-native","React Native",{"key":5,"name_tr":372,"name_en":6,"sort":373,"specializations":374},"Güvenlik",8,[375,376,377,378,379,380],{"key":239,"name":240,"field":5},{"key":132,"name":133,"field":5},{"key":145,"name":146,"field":5},{"key":139,"name":140,"field":5},{"key":142,"name":143,"field":5},{"key":136,"name":137,"field":5},{"key":382,"name_tr":383,"name_en":384,"sort":385,"specializations":386},"qa-test-automation","QA \u002F Test Otomasyonu","QA \u002F Test Automation",9,[387],{"key":239,"name":240,"field":382},{"key":389,"name_tr":390,"name_en":390,"sort":391,"specializations":392},"data-engineer","Data Engineer",10,[393],{"key":239,"name":240,"field":389},{"key":395,"name_tr":396,"name_en":397,"sort":398,"specializations":399},"game-dev","Oyun Geliştirme","Game Development",11,[400],{"key":239,"name":240,"field":395},{"key":402,"name_tr":403,"name_en":403,"sort":404,"specializations":405},"ml-engineer","ML Engineer",12,[406],{"key":239,"name":240,"field":402},[14,15,16],{"junior":409,"mid":411,"senior":412},{"questions":410,"median_sec":3},20,{"questions":410,"median_sec":3},{"questions":410,"median_sec":3},[414,10],"tr",[416,417],"google","github",21750,true]