Securing Gradle Builds
Build Engineer
Gradle
Course Outline
  1. Securing Gradle Builds
    Course Objectives
    Course Overview
  2. Securing Repositories
    Using Trusted Repositories
    Repository Content Filtering
  3. Securing Dependencies
    Checking for Known CVEs
    Checksum Verification
    Signature Verification
  4. Securing Gradle
    Verify Wrapper and Binary
  5. Securing Build Process
    Develocity Provenance Governor
  6. Feedback
    Survey
0%
Securing Gradle Builds
6 Sections

There are several methods malicious attackers use to compromise your products, even through your builds. Gradle provides a number of feature to protect your builds against attackers. Take this course to learn how to enable these features for your builds.


What You'll Learn:


Centralizing repository configuration:

  • For large projects with many subprojects, it can be hard to vet all the repositories

  • Learn how to centralize the repository definitions to help only trusted repositories are used


Verifying dependencies:

  • Learn how to be alerted when CVEs are discovered in dependencies

  • Enable Gradle features to validate and authenticate dependencies


Protect Gradle binaries:

  • Attackers have been known to try to replace Gradle binaries to compromise builds

  • Learn how to enable features to protect against this


Prerequisites:

  • Gradle Build Tool experience, including knowledge of core concepts and authoring build files (Kotlin DSL experience a plus)


By the end of this course, you'll be able to:

  • Better secure your Gradle builds


Enroll today and enhance your Gradle Build Tool skills to gain deeper insights into your builds and improve your development workflow!