Loading…
May 10-12, 2023
Vancouver, British Columbia, Canada + Virtual
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit North America 2023 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Pacific Daylight Time (UTC/GMT -8). To see the schedule in your preferred timezone, please select from the drop-down menu to the right, above "Filter by Date."

IMPORTANT NOTE: Timing of sessions and room locations are subject to change.

Thursday, May 11 • 11:55am - 12:35pm
SLSA Conformance - Kris Kooi, Google

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
Supply chain levels for software assurance, or SLSA (pronounced ‘salsa’), is a framework to reason about and improve the integrity of software artifacts. SLSA (https://slsa.dev) is seeing increased adoption across the industry and open source ecosystems.

In order to meet the highest level of build assurance, SLSA requires build systems to meet rigorous security standards. Many of these requirements are impractical to record in the artifact’s build provenance, so consumers have to decide whether to trust that the build system used to generate the artifact conforms to the SLSA specification. The community started the SLSA conformance program to help consumers make their trust decisions in a principled way. 

This talk describes the SLSA requirements for build systems, how the SLSA conformance program works, and how consumers can enforce their trust decisions during SLSA verification. After this talk, build system maintainers should understand the SLSA requirements and conformance program well enough to undergo the self-certification process, developers will be able to make informed decisions about which builders to use, and consumers will understand how to access public evidence that artifacts were built by SLSA-conformant build systems.

Speakers
KK

Kris K

Software Engineer, Google
Kris is a Software Engineer on Google’s Open Source Security Team, focusing on supply chain security.



Thursday May 11, 2023 11:55am - 12:35pm PDT
122 (Level 1)