{"repo":"slsa-framework/slsa","free":true,"listed":false,"github":"https://github.com/slsa-framework/slsa","clone":"git clone https://github.com/slsa-framework/slsa.git","description":"Supply-chain Levels for Software Artifacts","language":"HTML","stars":1912,"topics":["security","supply-chain-security","devops"],"license":null,"category":"security-tools","readme_excerpt":"SLSA (\"salsa\") is Supply-chain Levels for Software Artifacts SLSA (pronounced \"salsa\") is a security framework from source to service, giving anyone working with software a common language for increasing levels of software security and supply chain integrity. It’s how you get from safe enough to being as resilient as possible, at any link in the chain. Learning about SLSA See https://slsa.dev to learn about SLSA. What's in this repo? The primary content of this repo is the spec/ directory which contains the core SLSA specification and the www/ directory which contains the sources of the [slsa.dev] website. See the README.md in that directory for instructions on how to build the site. The spec/ folder on the main branch contains the current Draft specification. The released versions of the spec are found in the same folder but on the corresponding release branch (i.e., releases/v1.0 , releases/v1.2 , etc.) This repository also hosts SLSA's main [issue tracker], covering the website, specification, and overall project management. Other git repositories within the slsa-framework organization have repo-specific issue trackers. How to get involved See https://slsa.dev/community for ways to get involved in SLSA development. Active workstreams Workstream [Shepherd] ---------- ---------- [Build Level 4] Andrew McNamara (@arewm) [Attested Build Environments Track] Marcela Melara (@marcelamelara), Pavel Iakovenko (@paveliak) [Dependency Ingestion Track] Mike Lieberman (@mlieberman85) [","default_branch":null,"files":null,"tree":[],"storefront":"/r/slsa-framework","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/slsa-framework/slsa/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}