Supply-chain Levels for Software Artifacts (SLSA)¶
OpenSSF. (2023). Supply-chain Levels for Software Artifacts (SLSA).
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Attestation
- In the software case the principal is the publisher holding the signing key; the artifact is the binary; the mark is the code signature and build-provenance attestation binding the binary to its source revision and pipeline
This sourceSpecifies build-provenance attestations binding a binary to its source revision and build pipeline.
- In the software case the principal is the publisher holding the signing key; the artifact is the binary; the mark is the code signature and build-provenance attestation binding the binary to its source revision and pipeline
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:0134d56cb4b5 · see in the full table