5 lessons

Supply Chain Security

Your code is a minority of what you ship. Dependencies, lockfiles, provenance, malicious packages, CI/CD permissions and build integrity.

Asset→Threat→Attack Surface→Trust Boundary→Vulnerability→Exploit Path→Impact→Mitigation→Defense in Depth→Residual Risk

Every lesson below identifies the asset, attacker capability and boundary before naming the vulnerability. Controls are split into prevention, detection and recovery; residual risk is explicit.