Using Artifact Signing to Establish Provenance for SLSA
Blog post from Endor Labs
Endor Labs has introduced a low-code/no-code artifact signing capability that provides cryptographic signatures for software artifacts, aligning with the Supply-chain Levels for Software Artifacts (SLSA) Framework to enhance software supply chain security. This capability supports various use cases, such as Kubernetes admission control and traceability, and helps organizations achieve SLSA Build levels, which are associated with different security requirements. The SLSA framework categorizes its requirements into Source, Build, Provenance, and Common, with artifact signing being particularly relevant to Provenance, ensuring the traceability and authenticity of software artifacts. The latest SLSA version 1.0 introduces three levels of integrity guarantees, with higher levels requiring more stringent security measures. Endor Labs employs strong, keyless authentication in cloud environments and tamper-resistant measures to ensure provenance authenticity and security, allowing organizations to meet up to SLSA Level 3 certification. This enhances their security posture by preventing regressions to old, vulnerable artifact versions and protecting against supply chain threats.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.