vulns.co
/
GKData.io MCP

SLSA Community · 1 min read

SLSA v1.2: supply-chain security and build provenance

Learn to assess software supply-chain assurance using distinct source and build tracks. The build track progresses from recording provenance to authenticated hosted builds and stronger platform isolation. Build provenance connects an artifact to its builder, inputs, and build definition so consumers can evaluate whether its production matches expectations.

Open the reference Security StandardReviewed 2026-10-02

How to use this reference

Map documented build controls and provenance expectations to an approved architecture review; distinguish attestation presence from trusted verification.

Before reading

  • Basic familiarity with version control and continuous integration
  • Understanding of software artifacts, hashes, and digital-signature concepts

Context and limits

  • Build L1 provenance alone does not provide tamper protection.
  • The specification version is 1.2, while the build-provenance predicate identifier remains https://slsa.dev/provenance/v1; the page explains this major-version convention.
  • A recorded attestation is useful only within an explicit trust and verification model.

Related visual models

Sources and provenance

  1. Official stable entry point redirects to v1.2 SLSA Community · reviewed 2026-10-02
  2. Version 1.2 and Approved status SLSA Community · reviewed 2026-10-02
  3. SLSA Community release announcement dated 24 November 2025 SLSA Community · reviewed 2026-10-02
  4. Build-level distinctions and provenance limitations SLSA Community · reviewed 2026-10-02
  5. Build provenance model and predicate-version convention SLSA Community · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software