TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

SLSA, an End-to-End Framework for Supply Chain Integrity

109 pointsby rbinvalmost 4 years ago

4 comments

dane-pgpalmost 4 years ago
&gt; SLSA 4 is currently the highest level, requiring two-person review of all changes and a hermetic, reproducible build process.<p>I&#x27;m really glad that reproducible builds are being highlighted here. Potentially they pave the way for an SLSA 5 which requires that two separate entities independently carry out the build process and store the hash of the output in an append-only log somewhere, with their signatures.<p>Then maybe SLSA 6 could require that every commit on the repo also be signed, and finally SLSA 7 would require that all transitive dependencies themselves be SLSA 6, including the build environments, which would be bootstrapped from a minimal binary seed.<p>At that point, the question of &quot;Is this software trustworthy?&quot; becomes almost identical to &quot;Is the set of people who wrote and reviewed this software trustworthy?&quot;. That may not seem like a big improvement from where we are today, but hopefully it is cheaper to add honest reviewers than to compromise developers.
评论 #27579490 未加载
评论 #27576185 未加载
评论 #27583559 未加载
评论 #27582886 未加载
评论 #27584596 未加载
kylegillalmost 4 years ago
&gt; SLSA, pronounced “salsa”<p>I wonder if projects with easier to remember names linger in people&#x27;s minds longer.<p>Is this kind of phenomenon of fun names more a marketing thing? Or more a software engineers really love naming things thing?
评论 #27582279 未加载
Coutoalmost 4 years ago
I get the feeling that the update framework[1] fits in here somewhere, but I can&#x27;t point my finger where or how. Anyone willing to give a description on how they both could work together?<p>[1]: <a href="https:&#x2F;&#x2F;theupdateframework.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;theupdateframework.io&#x2F;</a>
TruthWillHurtalmost 4 years ago
You can always tell that they&#x27;re targeting executives when they use the basic slide deck &#x2F; powerpoint graphics and icons..