Tag

SLSA

0 views collected around this technical thread.

DevOps Engineer
DevOps Engineer
Dec 5, 2023 · Information Security

Using Witness for Software Supply Chain Security in Non‑GitHub Environments

This article explains how to generate and verify software artifact provenance with the Witness framework in non‑GitHub ecosystems, covering installation, key creation, configuration, running, signing, and policy verification to achieve higher SLSA levels.

ProvenanceSLSAWitness
0 likes · 10 min read
Using Witness for Software Supply Chain Security in Non‑GitHub Environments
DevOps Engineer
DevOps Engineer
Dec 4, 2023 · Information Security

Applying the SLSA Framework to Build, Sign, Publish, and Verify Python Packages on GitHub

This article demonstrates how to apply the SLSA (Supply chain Levels for Software Artifacts) framework to the Python ecosystem by building clean packages, generating provenance statements, uploading them to PyPI, and verifying the package origin using GitHub Actions and the slsa‑verifier tool.

GitHub ActionsProvenancePython
0 likes · 10 min read
Applying the SLSA Framework to Build, Sign, Publish, and Verify Python Packages on GitHub
DevOps
DevOps
Nov 9, 2023 · Information Security

Introducing SLSA: An End‑to‑End Framework for Software Supply Chain Integrity

This article translates Google's SLSA framework paper, explaining software supply chain threats, the four SLSA levels, mitigation strategies, a provenance generation example, and concluding with its impact on software security, while also noting related DevOps certification offerings.

ProvenanceSLSAdevops
0 likes · 12 min read
Introducing SLSA: An End‑to‑End Framework for Software Supply Chain Integrity
DevOps Engineer
DevOps Engineer
Jun 11, 2023 · Information Security

Understanding SLSA: A Guide to Software Supply Chain Security and Levels

This article explains the SLSA (Supply chain Levels for Software Artifacts) framework, outlines common software supply‑chain threats, details the four SLSA levels and their requirements, discusses limitations, and reviews tools such as OpenSSF Scorecard, slsa‑verifier and Sigstore for improving software artifact integrity.

SLSAartifact provenanceci-cd
0 likes · 15 min read
Understanding SLSA: A Guide to Software Supply Chain Security and Levels
Continuous Delivery 2.0
Continuous Delivery 2.0
Jan 10, 2023 · Information Security

Understanding Software Supply Chain Security and the SLSA Framework

The article explains why software supply chain security is increasingly critical, introduces the SLSA (Supply‑Chain Levels for Software Artifacts) framework and its three trust boundaries, outlines common risk points from code commit to package distribution, and discusses mitigation strategies such as mandatory code review, robot‑account controls, and automation.

Code ReviewSLSAci-cd
0 likes · 11 min read
Understanding Software Supply Chain Security and the SLSA Framework
DevOps
DevOps
Dec 5, 2022 · Operations

Key Findings from the 2022 Accelerate State of DevOps Report: Software Delivery, Organizational Performance, and Software Supply Chain Security

The 2022 Accelerate State of DevOps report, based on surveys of 33,000 professionals, reveals that software delivery performance, operational reliability, and organizational culture—especially high‑trust, low‑blame environments—drive organizational outcomes, while secure software supply chain practices such as SLSA and NIST SSDF further boost performance and reduce burnout.

CultureOrganizational PerformanceReliability
0 likes · 8 min read
Key Findings from the 2022 Accelerate State of DevOps Report: Software Delivery, Organizational Performance, and Software Supply Chain Security