SBOM Guide
SBOM basics

Other attestations than SBOM: SLSA

SLSA describes how software was built, not what it contains

An SBOM describes what a piece of software contains. It says nothing about how the software was built, or whether the file you received really comes from that build. That is the question SLSA deals with.

What SLSA is

SLSA (Supply chain Levels for Software Artifacts)1, pronounced "salsa", is a framework from the Open Source Security Foundation (OpenSSF). It describes requirements for the build process and a format for attesting that the requirements are met.

The attestation is called provenance. It is a signed document that states:

  • which artefact was built, identified by a checksum
  • from which repository and which commit
  • by which build system and with which configuration

Levels

SLSA divides the build process into levels. A higher level means it is harder to tamper with the build without it being noticed.

LevelRequirement
Build L1Provenance exists and describes how the artefact was built
Build L2The build runs on a build service that signs the provenance
Build L3The build service is hardened so that builds are isolated and the signing key is protected

SLSA and SBOM

DocumentAnswers
SBOMWhich components does the software contain?
VEXIs the software affected by a specific vulnerability?
SLSA provenanceWhere, how and by whom was the software built?

The documents complement each other. An SBOM for a component that cannot be tied to a known build says less than one that can.

Footnotes

  1. SLSA ↩

On this page