Skip to content

New dependency track filenames and editorial changes#1558

Open
mcevoy-building7 wants to merge 5 commits intoslsa-framework:mainfrom
mcevoy-building7:new-dep-track
Open

New dependency track filenames and editorial changes#1558
mcevoy-building7 wants to merge 5 commits intoslsa-framework:mainfrom
mcevoy-building7:new-dep-track

Conversation

@mcevoy-building7
Copy link

The new content of the SLSA Specification needed to be recombined to include additional content categories that had clearly defined heads that facilitated navigation and provided consistency for both users and contributors.

Some of the Dependency Track has been redistributed, terminology rearranged, headings clarified to reduce misunderstandings, new transitions and introductions added to existing content to enhance the flow of information.

A SLSA Track Specification Template has been created and submitted as Issue #1554 and this can assist contributors to add new content in the right places.

To create consistency in the filenames across all tracks, I have changed them to match the concepts of what each track must do:

  • Basics - introduction to track, track-specific terminology, and brief listing of the levels
  • Requirements - explains the detailed security requirements to achieve each level
  • Provenance - covers the distribution and verification of provenance metadata in the form of SLSA attestations
  • Verification - recommendations for how to verify artifacts and their SLSA provenance by human inspection
  • Assessment - describes the parts of the underlying platform that consumers should access with relevant questions

The new filenames are listed below:

depend-track-basics.md
depend-track-requirements.md
depend-track-provenance.md
depend-track-verification.md
depend-track-assessment.md

All the information from the original track (dependency-track.md) was kept in depend-track-basics.md or copied to depend-track-requirements.md. The remaining new files were created with placeholders and instructions for contributors who will fill in the missing information.

The old branch was dep-track and the new branch is new-dep-track.

@netlify
Copy link

netlify bot commented Jan 26, 2026

Deploy Preview for slsa ready!

Name Link
🔨 Latest commit 1b5f76b
🔍 Latest deploy log https://app.netlify.com/projects/slsa/deploys/6977385e6f195600080a258b
😎 Deploy Preview https://deploy-preview-1558--slsa.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: 🆕 New

Development

Successfully merging this pull request may close these issues.

1 participant