# slsa-framework/slsa

Supply-chain Levels for Software Artifacts

Repository: https://github.com/slsa-framework/slsa
Canonical: https://ross.abutalabs.com/products/slsa
Homepage: https://slsa.dev
Language: HTML
License: NOASSERTION
License Family: other
Topics: security, supply-chain-security, devops
Last push: 2026-08-09T11:32:43+00:00

## Health v2 (maintenance only)
Score: 75/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 96, release rhythm 35, longevity 100
- inputs: {"age_days": 2002, "days_push": 24, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1915, forks 290 (observed 2026-08-28T04:05:53.705646+00:00)

## What it is
SLSA (Supply-chain Levels for Software Artifacts) is an OpenSSF security framework and specification defining graduated levels of software supply chain integrity, from source to build to dependencies. This repository hosts the core specification, the slsa.dev website sources, and the project's issue tracker and workstreams.

## Use cases
- assess my project's software supply chain security level
- understand how to prevent dependency tampering attacks
- generate and verify build provenance attestations
- harden CI/CD builds against supply chain compromise
- learn about SLSA build track levels and requirements
- comply with supply chain security requirements like EO 14028

## When to choose
- you need an industry-consensus standard for supply chain integrity levels
- you are a build platform or package ecosystem implementer producing provenance
- you want a checklist of controls to incrementally harden builds, sources, and dependencies

## When to avoid
- you need runnable tooling rather than a specification - see slsa-framework's other repos
- you need vulnerability scanning or runtime security rather than supply chain integrity
- you want a turnkey compliance product rather than a framework to adopt yourself

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, documentation, developer-tools
- domain: security, developer-tools, documentation
- platform: self-hosted
- tags: supply-chain-security, specification, openssf, provenance, attestation, software-integrity, compliance-framework, devops, web-server

## Member repositories
- slsa-framework/slsa (main) score 75

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:53.705646+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:10:24.405604+00:00, confidence not recorded.
  - readme: https://github.com/slsa-framework/slsa (fetched 2026-08-28T04:05:53.705646+00:00, sha 5e4eb3222d3a)
  - homepage: https://slsa.dev (fetched 2026-08-29T10:49:39.613963+00:00, sha 478d6f3e05f2)
  - site_page: https://slsa.dev/spec/latest/threats-overview (fetched 2026-08-29T10:49:39.622962+00:00, sha 1571e5502cc0)
  - site_page: https://slsa.dev/spec/latest (fetched 2026-08-29T10:49:39.624732+00:00, sha 1aa82dc0f144)
- Data as of 2026-08-30T08:39:29.467469+00:00.
