openskills.info
SLSA Framework logoCourse Preview

SLSA Framework

SLSA is a framework for describing and improving the integrity of software from source change through build and distribution. Its tracks and levels help producers create evidence about software and help consumers decide whether that evidence meets their trust policy.

itSoftware supply chain security

SLSA Framework

Software reaches you through a chain of people, systems, and transformations. A source revision enters a build platform. The platform produces an artifact. A registry or other channel distributes that artifact. Each link creates a chance for unauthorized change.

SLSA gives you a shared way to reason about that chain. The name stands for Supply-chain Levels for Software Artifacts. The approved version 1.2 specification organizes requirements into independent tracks. Each track addresses one part of the supply chain. Levels within a track represent stronger guarantees.

SLSA is useful to three groups:

  • Producers use its requirements to improve how they create and release software.
  • Consumers verify evidence before they trust or use an artifact or source revision.
  • Infrastructure providers build the source control, build, package, and distribution systems that make those guarantees possible.

The central idea is evidence plus verification. A producer distributes provenance that describes how an artifact or source revision came to exist. A verifier authenticates that provenance and compares it with explicit expectations. Evidence without inspection does not enforce a policy.

Two tracks, two questions

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.