Skip to content

Learning about SLSA and considering action points #105

@consideRatio

Description

@consideRatio

Below is a quote from the Developing Secure Software course. It seems like SLSA could provide input on some low hanging fruit we could work systematically towards:

Supply chain Levels for Software Artifacts, or SLSA ("salsa"), is a security framework being developed as a checklist of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure. At the time of this writing it is still in development, but you should consider its recommendations. SLSA is being developed under the Open Source Security Foundation (OpenSSF). To learn more, see the SLSA home page.

Has anyone read through this?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions