Supply-Chain Levels for Software Artifacts (SLSA) - Security Framework Introduction
Eclipse Foundation via YouTube
Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Learn about Supply-chain Levels for Software Artifacts (SLSA), a comprehensive security framework and specification designed to incrementally improve supply chain security through industry consensus within the OpenSSF. Discover how SLSA organizes security measures into progressive levels that provide increasing security guarantees to prevent tampering, improve integrity, and secure packages and infrastructure throughout the software supply chain. Explore the framework's approach to transitioning from "safe enough" security to maximum resilience at every link in the supply chain. Gain insights into SLSA's current status, recent developments, and future roadmap, including the v1.0 release summary, Build Track levels, provenance and verification summary attestations (VSA), verification processes, and a sneak peek at the upcoming Source track. Understand real-world use cases and how SLSA addresses critical supply chain security problems facing the software industry today.
Syllabus
0:00 Welcome
1:42 Arnaud introduction
9:00 SLSA framework
12:50 SLSA use cases and the supply chain problem
15:30 SLSA offering
19:08 SLSA quick history
21:35 Release summary v1.0
24:20 SLSA Build Track levels
27:30 Provenance and verification summary attestations VSA
30:38 Verifying
34:50 Coming up on SLSA
38:50 Source track sneak peek
42:38 Q&A
Taught by
Eclipse Foundation