/slsa

Supply-chain Levels for Software Artifacts

Apache License 2.0Apache-2.0

SLSA: Supply-chain Levels for Software Artifacts

SLSA (pronunced "salsa") is an open source security framework to describe and verify what integrity looks like, giving anyone working with software a common language and a way to work at scale.

The best way to read about SLSA is to visit slsa.dev.

What's in this repo?

The primary content of this repo is the docs/ directory, containing the sources to the slsa.dev website. This directory includes the core SLSA specification.

Other files are auxiliary documents that may be useful for the development of SLSA.