Slide 14
Slide 14 text
14
SLSA PROVENANCE
It’s the verifiable information about software
artifacts describing where, when and how
something was produced.
Has its own SLSA requirements such as:
● It exists (L1)
● It’s authentic (L2)
● It’s unforgeable (L3)
Attestations include: build timestamps, build
parameters and environment, version control
metadata, source code details and materials (files,
scripts) consumed during the build.
Provenance example of SLSA Level 3
What’s provenance?