skip to content

SLSA & Build Provenance

SLSA levels turn 'a provenance file exists' into 'a builder the build cannot forge produced it', and in-toto attestations carry the claim. Interviewers read the ladder as pipeline maturity.

on this pageshow

explore

questions

page 2 of 2

Why does a provenance attestation stop verifying when a supplier rebuilds the same source revision?

level: middleimportance: nice to knowfreq 38%

basics

~20 s

A provenance statement binds to a digest of the artifact's bytes, not to the source revision. A rebuild that picks up a patched base produces different bytes and a new digest, so statements issued for the old build no longer match the artifact in hand.

open as a page

Your model registry requires a signature, an SBOM and provenance per checkpoint: which risks does that still leave open?

level: seniorimportance: nice to knowfreq 33%

basics

~20 s

The three claims answer who vouched, what is inside and how it was built. None of them says the recorded source was reviewed, whether a listed component is actually exploitable here, or whether anything enforces the checks at deploy time.

open as a page

A release ships an attestation whose predicate claims peer review was completed — what does that prove?

level: seniorimportance: nice to knowfreq 32%

basics

~10 s

Only that whoever held the signing key asserted that claim about those exact bytes. A predicate type names an assertion's schema, never its truth; value depends on who may issue that type.

open as a page

Can an on-prem, air-gapped build platform satisfy SLSA's hosted build platform requirement, and what must you show?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Yes. Hosted is a trust property, not a purchase: the build runs as a service the projects being built cannot modify. An on-prem builder qualifies when its operators are separate from its users and its configuration is outside their control.

open as a page

A regulator asks you to prove deployed bytes came from a source revision built four years ago, on a platform since decommissioned. What holds up?

level: principalimportance: nice to knowfreq 20%

basics

~20 s

An archived attestation is evidence only while its trust chain can still be evaluated; once the issuing platform and keys are gone it is unverifiable. A deterministic build with source, inputs and toolchain preserved lets an auditor re-derive the digest.

open as a page

A vendor's SLSA provenance carries a buildType URI you have never seen — do you accept it?

level: principalimportance: nice to knowfreq 30%

basics

~20 s

Not as provenance. buildType is the document defining which parameters exist and which a caller controls, so without it you cannot tell whether matching repository and ref pins the build. You have authenticity from the signature, not verified provenance.

open as a page

showing 31–36 of 36