Software Supply Chain

SLSA

Supply-chain Levels for Software Artifacts

Foundation Global OpenSSF Since 2021

A framework of graduated levels for build integrity and provenance: what a build platform must guarantee at each of build levels L0 to L3, and what the resulting provenance attestation must say about how an artefact was produced. Version 1.2 adds a source track alongside it.

It is the concrete answer to "prove this binary came from that source", the requirement underneath most modern software supply chain expectations.

At a glance

Category
Software Supply Chain
Jurisdiction
Global
Governance
OpenSSF
Status
v1.2 current, adding a source track; v1.0 released 2023
First released
2021

Links

Related frameworks

Other entries under Software Supply Chain.

See SLSA in context

Open the interactive Data Landscape for Regulation to compare SLSA against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.