What Supply-chain Levels for Software Artifacts (SLSA) v1.0 requires
The SLSA framework establishes four levels of software security assurance to protect against supply chain threats by requiring verifiable provenance for software artifacts. Compliance, as detailed in the 'Requirements' section, mandates progressively stricter controls on the build process, source code integrity, and provenance generation to prevent unauthorized modifications and ensure artifact integrity.
Pillar: Cloud & SaaS · Authority: Open Source Security Foundation (OpenSSF) · Version: 1.0.0 · Last updated:
Primary source: https://slsa.dev/spec/v1.0/
SHA-256 integrity: 4699b66b5226b498e56fe4e883bff35200c44016086848441d5f600d15855b54
Primary Citations — 6 traced to source
- SLSA v1.0 Specification: Requirements - Source
- SLSA v1.0 Specification: Requirements - Build
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/slsa-supply-chain-security-levels.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/slsa-supply-chain-security-levels.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/slsa-supply-chain-security-levels
- Back to registry: Browse all 10,085 compliance nodes