Awarded for completing Dependency Confusion and Typosquatting Attacks and passing its exam, demonstrating the ability to explain how dependency confusion and typosquatting each work and how they differ, identify the build configuration mistakes that create exposure to each, apply namespace reservation, package scoping, and exclusive private registry configuration as defensive controls, build a detection practice covering both public registry monitoring and build pipeline instrumentation, and execute the incident response sequence appropriate to a confirmed malicious package already pulled into a build.
Certificates are designed to be checked, not just displayed.
The credential is valid for 12 months from issue. Its public page states the expiry date, and renewing means passing the current exam again — so the credential always reflects the current material.