Developers who are serious about securing their code have cause to rejoice. The https://openssf.org/ is releasing https://slsa.dev/ version 1.0.
It defines four levels of increasing confidence in the security and integrity of the build, source code, and dependencies.
Key Milestone https://www.linkedin.com/in/brianbehlendorf/, the OpenSSF’s General Manager, emphasized that the stable release of SLSA v1.0 is a significant milestone in bolstering software supply chain security.
The release of SLSA v1.0 introduces a significant change in the framework’s structure, dividing its level requirements into multiple tracks that focus on specific areas of the software supply chain, such as build, source, and dependencies.