Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Global Accelerated Learning • Est. 1999
Glossary Term Supply-Chain Levels for Software Artifacts (SLSA)

Training Camp • Cybersecurity Glossary

What is Supply-Chain Levels for Software Artifacts (SLSA)?

SLSA Supply-chain Levels for Software Artifacts is an OpenSSF framework defining graduated provenance and integrity requirements for software builds.

Glossary > Application & API Security > Supply-Chain Levels for Software Artifacts (SLSA)

Understanding Supply-Chain Levels for Software Artifacts (SLSA)

Supply-chain Levels for Software Artifacts SLSA is an open security framework, originally created at Google and now hosted by the OpenSSF, that defines a graduated set of requirements for the integrity and provenance of software artifacts. It establishes incremental build and source levels designed to harden the software supply chain against tampering and ensure artifacts can be traced to verifiable build processes. Provenance attestations are a central component, allowing consumers to confirm how and where an artifact was produced.

Learn More About Supply-Chain Levels for Software Artifacts (SLSA):

Ready to Get Certified?

Turn knowledge into credentials with our instructor-led cybersecurity boot camps.

View All Courses →