-
Suggestion
-
Resolution: Unresolved
-
None
SLSA is a specification for describing and incrementally improving supply chain security, established by industry consensus:
The request is to add support for non-forgeable build provenance about build artifacts in Pipelines builds, to guarantee that the build has not been tampered with and contains the code it says it does.