Ross ROSS = Recommend OSS · open-source software intelligence for agents

slsa-framework/slsa resource

Supply-chain Levels for Software Artifacts observed · 2026-08-28

github.com/slsa-framework/slsa · homepage · HTML · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

75/100

  • Activity 96
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2002
  • days_rel: n/a
  • days_push: 24
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1915 stars · 290 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

SLSA (Supply-chain Levels for Software Artifacts) is an OpenSSF security framework and specification defining graduated levels of software supply chain integrity, from source to build to dependencies. This repository hosts the core specification, the slsa.dev website sources, and the project's issue tracker and workstreams.

Use cases

  • assess my project's software supply chain security level
  • understand how to prevent dependency tampering attacks
  • generate and verify build provenance attestations
  • harden CI/CD builds against supply chain compromise
  • learn about SLSA build track levels and requirements
  • comply with supply chain security requirements like EO 14028

When to choose

  • you need an industry-consensus standard for supply chain integrity levels
  • you are a build platform or package ecosystem implementer producing provenance
  • you want a checklist of controls to incrementally harden builds, sources, and dependencies

When to avoid

  • you need runnable tooling rather than a specification - see slsa-framework's other repos
  • you need vulnerability scanning or runtime security rather than supply chain integrity
  • you want a turnkey compliance product rather than a framework to adopt yourself

Facets

learning-resource · maturity active

security documentation developer-tools security developer-tools documentation self-hosted supply-chain-security specification openssf provenance attestation software-integrity compliance-framework devops web-server

4 sources

Member repositories

RepositoryRoleHealth v2
slsa-framework/slsamain75

For agents

markdown · JSON · MCP: product_card(name="slsa-framework/slsa")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem