codexproof

glossary / SLSA

Supply-chain Levels for Software Artifacts - Google's graduated framework (levels 1 through 3+) specifying how much provenance and build integrity an artifact carries, from "provenance exists" to "hardened, unfalsifiable builds."

in totosigstore
SLSA - The shelf: SLSA grades the factory's provenance; the red box grades nothing - it verifies serve-time custody

The shelf: SLSA grades the factory's provenance; the red box grades nothing - it verifies serve-time custody.

Etymology and backstory

pronounced salsa; grew from Google's internal Binary Authorization for Borg practices, published as an open framework in 2021 under the OpenSSF after SolarWinds made supply-chain compromise a boardroom word. The level system did for provenance what seatbelt ratings did for cars: made maturity legible and purchasable.

Ecosystem

GitHub and GitLab emit SLSA provenance; package registries verify it; procurement checklists ask for levels. The de facto vocabulary of software supply-chain policy.

In codexproof

cited as the maturity-model neighbor. SLSA grades the trustworthiness of BUILD provenance; codexproof's trust schema and revocation grade the authority behind EVIDENCE provenance at serve time. The rhyme worth saying in a consulting room: SLSA levels are to build pipelines what consumer-chosen anchors plus mandatory freshness are to evidence pipelines - graduated, checkable trust.

"SLSA made 'how much do you trust the build' a number; we make 'who vouches for this retrieved chunk' a checkable walk."
References: SLSA specification (OpenSSF); Lamb and Zacchiroli, "Reproducible Builds," IEEE Software (2022) for the adjacent reproducibility tradition.

All terms · Questions & answers · The verifier