Skip to content

standard

SLSA

SLSA (Supply-chain Levels for Software Artifacts) is a framework of security standards and provenance attestations for verifying software build integrity.

Known aliases

  • SLSA Build Level 3
  • slsa.dev/provenance/v1
  • SLSA L3
  • SLSA Level 3
  • SLSA provenance
  • Supply-chain Levels for Software Artifacts

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

A static denylist stopped one more prompt injection than no protection in a coding-agent study

Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence50
security1 publisher

Chainguard discloses 14 Java bugs that were fixed upstream but never got a CVE

Chainguard disclosed 14 Java vulnerabilities that were fixed upstream but never assigned a CVE, one rated critical and one high. Teams still on the affected versions got no scanner alert, some for years, because nobody announced the fixes when they landed at HEAD.

Publishers:chainguard.dev

Reality

Evidence40
Adoption25
Hype gap+10
Incentives75
Confidence45
security4 publishers

TRACE goes to the Linux Foundation, and the audit question becomes: show me the artifact

The Linux Foundation is taking over an open spec for hardware-signed agent runtime evidence. The producing side now has code and a spec; nobody has yet named who accepts the record.

Perspective Coverage

4 publishers
Builder
Builder 39%
Operator
Operator 46%
Investor
Investor 15%

Reality

Evidence55
Adoption20
Hype gap+30
Incentives70
Confidence60