SLSA & Build Provenance
SLSA levels turn 'a provenance file exists' into 'a builder the build cannot forge produced it', and in-toto attestations carry the claim. Interviewers read the ladder as pipeline maturity.
on this pageshowhide
explore
- Attestation Structure12 questions
- Which Claim Answers What3 questions
- In-Toto Statements4 questions
- Inside a Predicate5 questions
- SLSA Levels16 questions
- The Build Track4 questions
- Threats a Level Closes4 questions
- Trustworthy Build Platforms4 questions
- Reproducibility as Evidence4 questions
- Downstream Verification8 questions
- What a Consumer Checks4 questions
- Attestation Chains and Gaps4 questions
questions
page 2 of 2Why does a provenance attestation stop verifying when a supplier rebuilds the same source revision?
basics
~20 sA provenance statement binds to a digest of the artifact's bytes, not to the source revision. A rebuild that picks up a patched base produces different bytes and a new digest, so statements issued for the old build no longer match the artifact in hand.
Your model registry requires a signature, an SBOM and provenance per checkpoint: which risks does that still leave open?
basics
~20 sThe three claims answer who vouched, what is inside and how it was built. None of them says the recorded source was reviewed, whether a listed component is actually exploitable here, or whether anything enforces the checks at deploy time.
A release ships an attestation whose predicate claims peer review was completed — what does that prove?
basics
~10 sOnly that whoever held the signing key asserted that claim about those exact bytes. A predicate type names an assertion's schema, never its truth; value depends on who may issue that type.
Can an on-prem, air-gapped build platform satisfy SLSA's hosted build platform requirement, and what must you show?
basics
~20 sYes. Hosted is a trust property, not a purchase: the build runs as a service the projects being built cannot modify. An on-prem builder qualifies when its operators are separate from its users and its configuration is outside their control.
A regulator asks you to prove deployed bytes came from a source revision built four years ago, on a platform since decommissioned. What holds up?
basics
~20 sAn archived attestation is evidence only while its trust chain can still be evaluated; once the issuing platform and keys are gone it is unverifiable. A deterministic build with source, inputs and toolchain preserved lets an auditor re-derive the digest.
A vendor's SLSA provenance carries a buildType URI you have never seen — do you accept it?
basics
~20 sNot as provenance. buildType is the document defining which parameters exist and which a caller controls, so without it you cannot tell whether matching repository and ref pins the build. You have authenticity from the signature, not verified provenance.
showing 31–36 of 36