Meaning
Software supply chain security standard demonstrating that a build platform is secure against compromise and that its provenance is non-falsifiable. Achieving slsa level 3 requires that the build process runs in an isolated, ephemeral environment where the generated artifacts are accompanied by authenticated metadata. It protects against tamper attacks where malicious code is injected during the compilation or distribution phase.
Provenance Generation
Generating untamperable documentation of the build history requires a service that cannot be influenced by the build itself. This provenance must identify the source repositories, build entry points, and dependencies used to create the final executable. If a developer attempts to modify these files during compilation, the automated build platform blocks the release, ensuring that the source matches the artifact.
Ephemeral Environment
The build must occur on single-use infrastructure that is destroyed immediately after the compilation completes. Using ephemeral environments prevents persistent backdoors or cached exploits from carrying over between subsequent builds. This isolation is a critical requirement for achieving the high levels of supply chain integrity demanded by enterprise clients.
Security Audit
Organizations must undergo continuous audits to verify that their build pipelines meet these stringent security constraints. When a platform claims compliance, it must demonstrate that its signing keys are securely managed outside the build runtime. This verification reduces the risk of credential theft.