SLSA
#セキュリティ
#Sigstore
#サプライチェーン攻撃
概要
-
Supply-chain Levels for Software Artifacts
Provenance and trust - Docs - JSR
ツール
slsa-verifier
-
slsa-verifier is a tool for verifying
SLSA
provenance that was generated by CI/CD builders.
-
Language-agnostic
SLSA
provenance generation for Github Actions
関連ページ
JSR
aqua