Meaning
Adherence to the levels defined by the software supply chain levels for software artifacts framework ensures that code remains verifiable from source to deployment. Achieving slsa compliance requires a graduated approach to securing the build process and the underlying infrastructure. The framework provides a set of standards that protect against tampering and improve the integrity of software packages.
It is used by organizations to measure the maturity of their development pipelines.
Maturity Level
Four distinct tiers define the security requirements for an organization as it progresses toward full protection. To reach a specific level of slsa compliance, a project must demonstrate that its build process is automated and produces verifiable provenance. Higher levels require the build to occur in an isolated environment where no person has administrative access during the run.
This progression ensures that the software cannot be modified by a rogue actor or a compromised developer account. Each step builds a stronger wall against supply chain attacks.
Source Integrity
Version control systems must record every change and identify the author of every commit. Maintaining slsa compliance at the source level means that the code history is immutable and cannot be rewritten. This requirement ensures that auditors can verify the exact state of the code at any point in time.
It provides the foundation for the automated build and signing phases that follow.
Build Requirement
Build platforms must generate a signed record of the process that includes all input dependencies. This documentation is a mandatory part of slsa compliance for production software. Verification is mandatory.