About Red Hat Advanced Developer Suite - software supply chain


Red Hat Advanced Developer Suite - software supply chain 1.7

Learn how to secure your software development lifecycle with Red Hat Advanced Developer Suite - software supply chain.

Red Hat Advanced Developer Suite - software supply chain Documentation Team

Abstract

This document provides an overview of the Red Hat Advanced Developer Suite - software supply chain RHADS - SSC, detailing its key features, technologies, and how it empowers teams to build, test, and deploy secure applications efficiently.

Preface

Red Hat Advanced Developer Suite - software supply chain (RHADS - SSC) is a comprehensive suite of tools designed to enhance and secure the software supply chain for developers and DevOps teams.

Securing your software supply chain is critical to prevent software vulnerabilities. RHADS - SSC embeds security throughout the software development lifecycle (SDLC), enabling teams to innovate confidently while adhering to the highest security standards.

Chapter 1. Overview

Red Hat Advanced Developer Suite (RHADS) was previously known as Red Hat Trusted Application Pipeline. Starting with version 1.6, it became part of a new Red Hat offering Red Hat Advanced Developer Suite.

RHADS is a DevSecOps framework that integrates security from project inception to production. It reduces security risks in continuous integration/continuous delivery (CI/CD) pipelines by embedding security checks, ensuring artifact integrity, and enabling compliance with standards such as Supply chain Levels for Software Artifacts (SLSA).

1.1. Key features

  • Ready-to-use templates: Start project quickly with customizable templates that include established security practices. Reduce setup time and focus on delivering secure software sooner.
  • Secure CI/CD pipelines: Build, test, and deploy container images securely using pre-configured pipelines integrated with your Git repository. Apply security measures at every stage to reduce risks before code reaches production.
  • Integrated security checks: Detect and address potential vulnerabilities with detailed insights to help understand the potential threats.
  • SBOM management: Automatically generate a Software Bill of Materials (SBOM) for each pipeline. Sign attestations and maintain a clear record of component origins, ensuring traceability and compliance throughout the software life cycle.
  • Tamper-proof artifact signing: Apply cryptographic signatures to code submissions and related artifacts. Maintain an immutable log of build and deployment activities to preserve trust and integrity.
  • Compliance and policy enforcement: Comply with standards such as Supply chain Levels for Software Artifacts (SLSA) Level 3 and enterprise requirements. Configure approval gates, run vulnerability scans, and enforce policies so only verified, compliant artifacts move forward.

1.2. Integrated technologies

Red Hat Advanced Developer Suite (RHADS) integrates with industry-leading platforms and tools:

Expand
Component or TechnologyDescription

Red Hat Developer Hub (RHDH)

A self-service portal that streamlines development and integrates security best practices from the get-go.

Red Hat Trusted Artifact Signer (RHTAS)

Enhances software integrity through signature and attestation, ensuring all artifacts are secure and authentic.

Red Hat Trusted Profile Analyzer (RHTPA)

Automates the creation and management of SBOMs, providing transparency and compliance in your software supply chain.

Red Hat Advanced Cluster Security (RHACS)

Automates the scanning of artifacts for vulnerabilities.

OpenShift GitOps

Automates application deployment and lifecycle management, ensuring consistent versions of app definitions, configurations, and environments.

OpenShift Pipelines

Automates the CI/CD processes with visibility and control over build, test, and deployment workflows.

1.3. Configuration options

Red Hat Advanced Developer Suite allows flexibility in CI/CD management, source repositories, and artifact registries:

Expand
CategoryOptions

CI/CD pipelines

  • Tekton (Default)
  • Jenkins
  • GitHub Actions
  • GitLab CI
  • Azure CI (Technology preview)
Note

All CI pipelines except Tekton conform to SLSA Build L2. Tekton conforms to Build L3.

Source repositories

  • GitHub (Default)
  • GitLab
  • Bitbucket Cloud

Artifact registries

  • Quay
  • JFrog Artifactory
  • Sonatype Nexus Repository

Chapter 2. Development workflow

Red Hat Advanced Developer Suite (RHADS) integrates security at every step of the DevSecOps workflow:

  • Start with secure templates: Leverage pre-built templates from RHDH for a secure foundation. These templates include code repositories, documentation, and pre-configured CI/CD pipelines.
  • Develop and modify code: Modify your code after creating the application. Each code change triggers a pipeline that automatically performs security checks, including artifact signing, vulnerability scanning, and SBOM generation.
  • OpenShift GitOps driven deployment: RHADS enforces security policies throughout the development lifecycle, from development to production, using Conforma. This ensures that only compliant builds are deployed.





Revised on 2025-09-24 19:12:30 UTC

Legal Notice

Copyright © 2025 Red Hat, Inc.
The text of and illustrations in this document are licensed by Red Hat under a Creative Commons Attribution–Share Alike 3.0 Unported license ("CC-BY-SA"). An explanation of CC-BY-SA is available at http://creativecommons.org/licenses/by-sa/3.0/. In accordance with CC-BY-SA, if you distribute this document or an adaptation of it, you must provide the URL for the original version.
Red Hat, as the licensor of this document, waives the right to enforce, and agrees not to assert, Section 4d of CC-BY-SA to the fullest extent permitted by applicable law.
Red Hat, Red Hat Enterprise Linux, the Shadowman logo, the Red Hat logo, JBoss, OpenShift, Fedora, the Infinity logo, and RHCE are trademarks of Red Hat, Inc., registered in the United States and other countries.
Linux® is the registered trademark of Linus Torvalds in the United States and other countries.
Java® is a registered trademark of Oracle and/or its affiliates.
XFS® is a trademark of Silicon Graphics International Corp. or its subsidiaries in the United States and/or other countries.
MySQL® is a registered trademark of MySQL AB in the United States, the European Union and other countries.
Node.js® is an official trademark of Joyent. Red Hat is not formally related to or endorsed by the official Joyent Node.js open source or commercial project.
The OpenStack® Word Mark and OpenStack logo are either registered trademarks/service marks or trademarks/service marks of the OpenStack Foundation, in the United States and other countries and are used with the OpenStack Foundation's permission. We are not affiliated with, endorsed or sponsored by the OpenStack Foundation, or the OpenStack community.
All other trademarks are the property of their respective owners.
Red Hat logoGithubredditYoutubeTwitter

Learn

Try, buy, & sell

Communities

About Red Hat Documentation

We help Red Hat users innovate and achieve their goals with our products and services with content they can trust. Explore our recent updates.

Making open source more inclusive

Red Hat is committed to replacing problematic language in our code, documentation, and web properties. For more details, see the Red Hat Blog.

About Red Hat

We deliver hardened solutions that make it easier for enterprises to work across platforms and environments, from the core datacenter to the network edge.

Theme

© 2026 Red Hat
Back to top