You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
SLSA ("salsa") is Supply-chain Levels for Software Artifacts
SLSA (pronounced "salsa") is a security framework from source to service, giving anyone working with software a common language for increasing levels of software security and supply chain integrity. It’s how you get from safe enough to being as resilient as possible, at any link in the chain.
The primary content of this repo is the docs/ directory, which contains
the core SLSA specification and sources to the slsa.dev website. See the
README.md in that directory for instructions on how to build the site.
This repository also hosts SLSA's main issue tracker, covering the website,
specification, and overall project management. Other git repositories within the
slsa-framework organization have
repo-specific issue trackers.
SLSA is an OpenSSF project. See
slsa-framework/governance for
governance information, including current steering committee members.
To include the steering committee on GitHub, use
@slsa-framework/slsa-steering-committee.
License
All SLSA specification content contributed following adoption of the Community
Specification governance model is provided under the
Community Specification License 1.0.
Pre-existing portions of the SLSA specification from contributors who have not
subsequently contributed under the Community Specification License 1.0 following
its adoption are provided under the
Apache License 2.0.