Securing the software supply chain with the SLSA framework
blog.trailofbits.com | blog | #supply-chain | #open-source | #pypi | #supply-chain-security | #pep-740 | #provenance | #slsa
Summary
An overview of the SLSA framework's Build Levels 1-3, signed build provenance from CI/CD platforms, PEP 740 bringing SLSA provenance to PyPI, and how consumers can verify artifact origins.
- Published
- Collected
Skip to content