Other attestations than SBOM: SLSA
SLSA describes how software was built, not what it contains
An SBOM describes what a piece of software contains. It says nothing about how the software was built, or whether the file you received really comes from that build. That is the question SLSA deals with.
What SLSA is
SLSA (Supply chain Levels for Software Artifacts)1, pronounced "salsa", is a framework from the Open Source Security Foundation (OpenSSF). It describes requirements for the build process and a format for attesting that the requirements are met.
The attestation is called provenance. It is a signed document that states:
- which artefact was built, identified by a checksum
- from which repository and which commit
- by which build system and with which configuration
Levels
SLSA divides the build process into levels. A higher level means it is harder to tamper with the build without it being noticed.
| Level | Requirement |
|---|---|
| Build L1 | Provenance exists and describes how the artefact was built |
| Build L2 | The build runs on a build service that signs the provenance |
| Build L3 | The build service is hardened so that builds are isolated and the signing key is protected |
SLSA and SBOM
| Document | Answers |
|---|---|
| SBOM | Which components does the software contain? |
| VEX | Is the software affected by a specific vulnerability? |
| SLSA provenance | Where, how and by whom was the software built? |
The documents complement each other. An SBOM for a component that cannot be tied to a known build says less than one that can.