Source library · 320 curated entries

Where every claim in SecProve comes from.

A dense reading catalog. Every claim is footnoted. Sort by source, filter by pillar, type, or recency. Built for analysts who want to see what we are standing on.

320SOURCES
143ORGS
50DOMAINS
320ADDED · 90 DAYS
Pillar · multi-selectall 4 selected
Domainsselect pillar(s) above
Browsing the full corpus. Pick pillars above to narrow to specific domains.
6 sources · matching filters · sorted by citation density
Sort
ACybersecurity6 sources
01

Open-source project for signing, verifying, and protecting software supply chains. Keyless signing for artifacts.

Test your knowledge · A13
02
SolarWinds / Log4Shell Case StudiesMultiple (CISA, Mandiant, Microsoft)

The two defining supply chain incidents of recent years. CISA's postmortem reports are primary sources for scenario-based questions about detection, response, and prevention.

GuideIntermediateA13 · Supply Chain SecurityNEW · 22d ago
Test your knowledge · A13
03

Practices for identifying, assessing, and mitigating cyber supply chain risks. Covers acquisition, development, and operations.

FrameworkIntermediateA13 · Supply Chain SecurityNEW · 1mo ago
Test your knowledge · A13
04

Cybersecurity Supply Chain Risk Management. Integrates C-SCRM into the RMF. Covers acquisition, supplier assessment, and ongoing monitoring.

FrameworkIntermediateA13 · Supply Chain SecurityNEW · 22d ago
Test your knowledge · A13
05
OpenSSF ScorecardOpen Source Security Foundation

Automated security health checks for open source projects. Checks branch protection, dependency pinning, fuzzing, SAST. Good for practical supply chain assessment questions.

ToolIntermediateA13 · Supply Chain SecurityNEW · 22d ago
Test your knowledge · A13
06

Annual analysis of open source usage and vulnerability data. Key stats on open source in commercial codebases (typically 70-80%+). Grounds supply chain and AppSec questions in real data.

Test your knowledge · A4

Ready to test what you've learned?

Our questions are built directly from these resources. Take a quiz and see how your knowledge stacks up.