Skip to content

Conversation

@xbcsmith
Copy link
Contributor

@xbcsmith xbcsmith commented Dec 3, 2025

A blog post based on a talk given at ATO 2025 on Supply Chain Security and SLSA

A talk about creating automation, shifting left, attack vectors, attestations, verification, zero-trust, and SLSA.

In the talk I cover creating automation, shifting left, attack vectors, attestations, verification, zero-trust, and how the SLSA spec helps implement solutions for each. The main take away is that security needs to be applied everywhere in the pipeline. The talk should lead to a greater discussion around the challenges of securing the supply chain, supporting EO 14028 and ISO27001, and improving the security posture of your pipelines.

Talk Link

@netlify
Copy link

netlify bot commented Dec 3, 2025

Deploy Preview for slsa ready!

Name Link
🔨 Latest commit 4f0b4f1
🔍 Latest deploy log https://app.netlify.com/projects/slsa/deploys/694021ff263944000825c7f0
😎 Deploy Preview https://deploy-preview-1528--slsa.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@xbcsmith xbcsmith changed the title docs(blog): Supply Chain Robots, Electric Sheep, and SLSA blog: Supply Chain Robots, Electric Sheep, and SLSA Dec 3, 2025
@xbcsmith xbcsmith changed the title blog: Supply Chain Robots, Electric Sheep, and SLSA blog: supply chain robots, electric sheep, and SLSA Dec 3, 2025
Copy link
Member

@arewm arewm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this blog proposal. Did you use voice-to-text? It reads exactly like you talk.

I left a couple of comments to try to help with clarity.

@xbcsmith
Copy link
Contributor Author

xbcsmith commented Dec 4, 2025

Thanks for this blog proposal. Did you use voice-to-text? It reads exactly like you talk.

I left a couple of comments to try to help with clarity.

Didn't use voice-to-text just banged it out on the keyboard like the old days...

@xbcsmith xbcsmith requested a review from arewm December 12, 2025 15:09
@arewm
Copy link
Member

arewm commented Dec 12, 2025

According to CONTRIBUTING, we need another maintainer to approve: https://github.com/slsa-framework/slsa/blob/main/CONTRIBUTING.md#pull-request-types

@TomHennen , would you mind looking at this?

Copy link
Contributor

@TomHennen TomHennen left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, I was waiting for @arewm to approve since he knows the content best. :)

@arewm arewm self-requested a review December 15, 2025 02:29
Copy link
Member

@arewm arewm left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

You need to remove the old file as well or you'll get a double-post. :)

@TomHennen TomHennen merged commit 2ed1304 into slsa-framework:main Dec 15, 2025
6 checks passed
@github-project-automation github-project-automation bot moved this from 🆕 New to ✅ Done in Issue triage Dec 15, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants