<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SLSA 1.1 on</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/compliance/slsa/</link><description>Recent content in SLSA 1.1 on</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>Copyright (c) 2023 Chainguard</copyright><lastBuildDate>Tue, 14 Feb 2023 08:49:15 +0000</lastBuildDate><atom:link href="https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/compliance/slsa/index.xml" rel="self" type="application/rss+xml"/><item><title>Introduction to SLSA</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/compliance/slsa/what-is-slsa/</link><pubDate>Tue, 14 Feb 2023 08:49:15 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/compliance/slsa/what-is-slsa/</guid><description>&lt;p&gt;SLSA (pronounced “salsa”), or Supply chain Levels for Software Artifacts, is a security framework consisting of standards and controls that prevent tampering, improve integrity, and secure packages and infrastructure. While cyberattacks like &lt;a href="https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/software-security/glossary/#solarwinds-hack"&gt;SolarWinds&lt;/a&gt; and &lt;a href="https://www.reuters.com/technology/codecov-hackers-breached-hundreds-restricted-customer-sites-sources-2021-04-19/"&gt;Codecov&lt;/a&gt; have demonstrated the importance of protecting software from tampering and malicious compromise, the complexity of the software development lifecycle can leave many feeling unable to adequately understand or respond to these specific security issues.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://security.googleblog.com/2021/06/introducing-slsa-end-to-end-framework.html"&gt;Released by Google’s Open Source Security Team&lt;/a&gt; in 2021, SLSA was created as a framework to help software creators understand where and how they can harden their supply chain security practices, and help software consumers evaluate the integrity of a software product or component before they decide to use it. SLSA was also designed around the creation of verifiable metadata, so that software consumers can set automated policies to prevent the deployment of code that does not meet their preferred SLSA level.&lt;/p&gt;</description></item><item><title>SLSA Compliance at Chainguard</title><link>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/compliance/slsa/slsa-chainguard/</link><pubDate>Wed, 23 Jul 2025 01:24:23 +0000</pubDate><guid>https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/compliance/slsa/slsa-chainguard/</guid><description>&lt;p&gt;SLSA (pronounced &amp;ldquo;salsa&amp;rdquo;), or Supply chain Levels for Software Artifacts, is a security framework consisting of standards and controls that prevent tampering, improve integrity, and secure packages and infrastructure. It is described in depth in &lt;a href="https://deploy-preview-3422--ornate-narwhal-088216.netlify.app/compliance/slsa/what-is-slsa/"&gt;What is SLSA?&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;All Chainguard products — including Chainguard Containers, Guarded VMs, and Chainguard Libraries — are SLSA Level 3 compliant to provide confidence in the security of these products.&lt;/p&gt;
&lt;p&gt;This page describes what we have done to bring Chainguard products into full SLSA Level 3 compliance.&lt;/p&gt;</description></item></channel></rss>