Menu

#Slsa

2 posts

Feed·
2 of 2 posts
SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier
🖼️
0

SLSA Provenance Hands-on: Generate with GitHub Actions, Verify with slsa-verifier

DEV Community·kt·about 1 month ago
#Yi4O8yAJ

After SBOM and Cosign comes Provenance. Issue SLSA Build L3 provenance with slsa-github-generator and verify it with slsa-verifier, end to end on real machines.

15s
Read More
SLSA Deep Dive: Securing the Supply Chain Using Verifiable Levels
📰
0

SLSA Deep Dive: Securing the Supply Chain Using Verifiable Levels

DEV Community·kt·about 1 month ago
#7kDUhMln
#build#security#provenance#slsa#track#article

A complete teardown of the SLSA specification. We dissect the threat model, Build and Source track requirements, Provenance structure, and the verification flow with diagrams.

15s
Read More