Slide 15
Slide 15 text
Protecting Builds
Level 1
▪ no builds using unsigned
or unverified commits
▪ build server configuration
is codified and tested
Level 3
▪ all builds have a validated
software bill of materials
▪ all builds are hermetic, all
dependencies packaged
Level 2
▪ actively create and store
tamper-proof build logs
▪ build server configuration
uses strong addressing