-
Type:
Suggestion
-
Resolution: Unresolved
-
Component/s: Product - Compliance
-
None
SLSA is a specification for describing and incrementally improving supply chain security, established by industry consensus:
The request is to add support for non-forgeable build provenance about build artifacts in Pipelines builds, to guarantee that the build has not been tampered with and contains the code it says it does.