Software Supply Chain
SLSA
Supply-chain Levels for Software Artifacts
A framework of graduated levels for build integrity and provenance: what a build platform must guarantee at each of build levels L0 to L3, and what the resulting provenance attestation must say about how an artefact was produced. Version 1.2 adds a source track alongside it.
It is the concrete answer to "prove this binary came from that source", the requirement underneath most modern software supply chain expectations.
At a glance
- Category
- Software Supply Chain
- Jurisdiction
- Global
- Governance
- OpenSSF
- Status
- v1.2 current, adding a source track; v1.0 released 2023
- First released
- 2021
Links
Related frameworks
Other entries under Software Supply Chain.
- SPDX: System Package Data Exchange
- CycloneDX: CycloneDX Bill of Materials
- Sigstore
- in-toto: in-toto Attestation Framework
See SLSA in context
Open the interactive Data Landscape for Regulation to compare SLSA against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.