أمان سلسلة التوريد والتحقق من الوحدات
احمِ عمليات نشر WASM من العبث والتبعيات الخبيثة عبر ممارسات التوقيع والتحقق وإثبات المصدر.
أمان سلسلة التوريد والتحقق من الوحدات درس مجاني في WebAssembly (WASM) for High Performance Apps على CoddyKit. هذا هو الدرس 4 من أصل 4. يمكنك قراءة الدرس كاملاً أدناه مجاناً — ثم تمرن عليه مباشرة في المتصفح باستخدام محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7. هذا الدرس جزء من مسار التعلم في WebAssembly (WASM) for High Performance Apps، وتقدمك يتزامن عبر الويب وتطبيق CoddyKit. تتضمن دورة WebAssembly (WASM) for High Performance Apps 4 دروس في المجموع.
بعض أجزاء هذا الدرس لم تُترجم بعد وتظهر باللغة الإنجليزية.
Beyond the Sandbox
The WASM sandbox protects the host at runtime, but it does not guarantee the module you run is the one you trust. Supply chain security covers where the bytes came from.
Threats to Address
Key risks:
- Tampered modules in transit or storage
- Compromised build pipelines
- Malicious third-party WASM dependencies
Integrity with Hashing
Pin a module by its content hash so any byte change is detected before instantiation.
import crypto from "node:crypto";
import fs from "node:fs";
const bytes = fs.readFileSync("app.wasm");
const hash = crypto.createHash("sha256").update(bytes).digest("hex");
if (hash !== EXPECTED) throw new Error("integrity check failed");Signing Modules
Cryptographic signatures prove authorship. The publisher signs the module; the host verifies with the corresponding public key before running it.
Verifying Before Instantiate
Always verify integrity/signature before calling WebAssembly.instantiate — never run untrusted bytes and check afterward.
Provenance & Attestation
Build attestations (e.g. SLSA) record how and where a module was built, letting you reject artifacts not produced by your trusted pipeline.
Auditing Dependencies
A WASM module may bundle third-party code. Track a bill of materials (SBOM) and scan dependencies for known vulnerabilities.
Reproducible Builds
Deterministic builds let independent parties rebuild the same module and confirm the hash matches, defeating hidden tampering in the toolchain.
Registry Security
When pulling modules from a registry, use signed references and pin versions/digests rather than mutable tags to prevent substitution attacks.
Runtime Allowlisting
Maintain an allowlist of approved module hashes in production. The host refuses to instantiate anything not on the list.
Defense in Depth
Combine sandbox + signing + provenance + capability limits. No single layer is sufficient; together they shrink the attack surface dramatically.
Quick Check
When should signature verification happen?
Recap
Supply chain security complements the runtime sandbox: use hashing for integrity, signatures for authorship, provenance/SBOM for trust, verify before instantiation, and allowlist approved hashes in production.
الأسئلة الشائعة
هل درس «أمان سلسلة التوريد والتحقق من الوحدات» مجاني؟
نعم — نص درس «أمان سلسلة التوريد والتحقق من الوحدات» كامل متاح مجاناً هنا على الويب. لتمرينه بشكل تفاعلي (محرر أكواد مدمج ومدرس ذكاء اصطناعي متاح 24/7) وفتح باقي دورة WebAssembly (WASM) for High Performance Apps، انتقل إلى CoddyKit PRO. تتضمن دورة WebAssembly (WASM) for High Performance Apps 4 دروس في المجموع.
ماذا ستتعلم في «أمان سلسلة التوريد والتحقق من الوحدات»؟
احمِ عمليات نشر WASM من العبث والتبعيات الخبيثة عبر ممارسات التوقيع والتحقق وإثبات المصدر. تتمرن على WebAssembly (WASM) for High Performance Apps مع أكواد عملية تشغلها مباشرة في المتصفح، ومدرس ذكاء اصطناعي متاح 24/7 يجيب على أسئلتك أثناء عملك.
هل أحتاج إلى خبرة سابقة لأبدأ WebAssembly (WASM) for High Performance Apps؟
لا تُشترط خبرة سابقة. WebAssembly (WASM) for High Performance Apps على CoddyKit منظم للمبتدئين حتى المتقدمين، لذا يمكنك البدء من هنا أو من البداية والتقدم بسرعتك الخاصة. هذا هو الدرس 4 من أصل 4.
كم من الوقت يستغرق درس «أمان سلسلة التوريد والتحقق من الوحدات»؟
معظم دروس CoddyKit تستغرق حوالي 5–10 دقائق. كل منها موجز وتفاعلي، لذا تحرز تقدماً مستمراً وتستأنف من حيث توقفت عبر الويب والتطبيق.
هل يمكنني كتابة وتشغيل أكواد في درس WebAssembly (WASM) for High Performance Apps هذا؟
نعم. كل درس في WebAssembly (WASM) for High Performance Apps يتضمن محرر أكواد مدمج، لذا تكتب وتشغل أكواداً حقيقية مباشرة في متصفحك وتحصل على تعليقات فورية من الذكاء الاصطناعي — بدون إعداد محلي.
جميع الدروس في هذه الدورة
- نموذج أمان WASM
- العزل والصلاحيات
- استراتيجيات النشر في بيئة الإنتاج
- أمان سلسلة التوريد والتحقق من الوحدات