Kai Ole Hartwig

name of the term: SLSA
descriptions of the term:

Definition

Definition. SLSA (Supply-chain Levels for Software Artifacts) is a framework that describes the integrity of the software supply chain in graded levels. It defines measures that make an artefact traceable and verifiable. The goal: prove that it really comes from the expected source code and build process, and was not tampered with on the way.

Why it matters. SLSA targets attacks that do not touch the source code itself, but the path from source to shipped artefact. For mid-sized platforms it adds a second question to the SBOM. The SBOM says what is inside. SLSA says whether the origin can be trusted. Supply chain security becomes verifiable instead of claimed.

Related. SBOM, Supply Chain Security, Software Provenance, DevSecOps

Type of term: acronym
Language of the term (2 char ISO code): en
Back