Supply-chain Levels for Software Artifacts (SLSA), Version 1.0¶
Open Source Security Foundation. (2023). Supply-chain Levels for Software Artifacts (SLSA), Version 1.0.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Primes¶
- Untrusted Input Execution
- In supply chains it is the trusted-component breach: an assembler, compiler, or build pipeline ingests a component (a dependency package, a hardware part, a vendor library, an upstream patch) as inert input to be incorporated, and a malicious or tampered component crosses into the assembled artifact carrying control the assembler never re-inspects — a typosquatted package whose install script runs with the build's privileges, a back-doored library linked into a trusted binary, a contaminated reagent or counterfeit part incorporated because provenance was assumed rather than verified.
This sourceDefines the supply-chain integrity framework — build provenance, signed artifacts, hermetic builds — addressing the trusted-component breach where a tampered dependency executes with the build pipeline's privilege; the structural provenance fix.
- In supply chains it is the trusted-component breach: an assembler, compiler, or build pipeline ingests a component (a dependency package, a hardware part, a vendor library, an upstream patch) as inert input to be incorporated, and a malicious or tampered component crosses into the assembled artifact carrying control the assembler never re-inspects — a typosquatted package whose install script runs with the build's privileges, a back-doored library linked into a trusted binary, a contaminated reagent or counterfeit part incorporated because provenance was assumed rather than verified.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:0786136ad9ec · see in the full table