Container Supply Chain Security Pipeline
Interactive container CI/CD supply-chain pipeline: watch an image move through vulnerability scanning, SBOM generation, cryptographic signing and Kubernetes admission control, then compare a clean build against a build compromised by an unauthorized dependency.
This simulator walks a container image through a real DevSecOps CI/CD pipeline — code, base image, dependencies, build, registry and cluster deployment — pausing at each of the four checkpoints teams actually use to keep a supply chain trustworthy: vulnerability scanning, SBOM generation, cryptographic image signing and Kubernetes admission control. Switch between a clean build and one compromised by an unauthorized dependency to see exactly which checkpoint catches the problem, and which ones a stealthy, SolarWinds-style build-time compromise can slip past.
3D container CI/CD pipeline from code to production: watch an image cross four real DevSecOps checkpoints (CVE vulnerability scan, SBOM generation, Sigstore/cosign signing, Kubernetes admission control). Toggle a clean build against one compromised by an unauthorized build-time dependency and see it pass known-CVE scanning yet get refused by the admission controller for lacking a valid signature.
3D · Three.js / WebGL renderer · 60 FPS target · runs fully client-side, no install