Skip to content

SLSA Conformance #76

@fraxken

Description

@fraxken

I need to dig around SLSA conformance and NPM provenance for NodeSecure. There is two aspects:

  • How this could improve security of Github orgs
  • How can we implement metrics about that in our tools/packages

Here is a french talk about SLSA and Sigstore.

Also see the official website: https://slsa.dev/

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions