SLSA
#セキュリティ #Sigstore #サプライチェーン攻撃
概要
- Supply-chain Levels for Software Artifacts
Provenance and trust - Docs - JSR
ツール
slsa-verifier - slsa-verifier is a tool for verifying SLSA provenance that was generated by CI/CD builders.
- Language-agnostic SLSA provenance generation for Github Actions
関連ページ
JSR
aqua