Achieving SLSA Certification with a “Bring-Your-Own-Builder” Framework

QCon New York 2023

Session Software Supply Chain Security

Achieving SLSA Certification with a “Bring-Your-Own-Builder” Framework

Tuesday Jun 13 / 04:10PM EDT, Dumbo / Navy Yard

Abstract

Supply-chain Levels for Software Artifacts, or SLSA (pronounced “salsa”), is a security framework to reason about and improve the integrity of released artifacts. With the recent release of SLSA version 1.0, SLSA is seeing increased adoption, both from industry and open source projects. The framework provides guidelines and compliance programs for infrastructure providers to integrate SLSA requirements in their build platforms. However, implementing a SLSA-compliant builder requires expertise in both SLSA and the underlying platform used to build it.

Come to this talk to learn about recent work that allows you to wrap existing tools (in the form of a binary, a GitHub Action, or a container) into a SLSA-compliant builder with minimal effort on existing open-source CI/CD platforms. We will show how SLSA builders for several package managers, such as npm and maven, are implemented with this framework on GitHub Actions. We will also report the lessons learned and the challenges we faced, in the hope it will help others that our experiences will help others implement trusted builders more effectively.

At the end of this talk, attendees will have enough background to make a tool attest to its output using SLSA provenance.

Topics

Software Supply Chain Security Security Open Source
76% senior dev or higher
1:11 speaker ratio
60+ practitioners

QCon New York 2023 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.

Share

From the same track

Tuesday 13 June

10:35 Dumbo / Navy Yard Session WebAssembly Wasm: What is Universal Compute Good For? Sean Isom Senior Engineer @Adobe 11:50 Dumbo / Navy Yard Session Security Sigstore: Secure and Scalable Infrastructure for Signing and Verifying Software Billy Lynch, Zack Newman 13:40 Dumbo / Navy Yard Session WebAssembly Build Features Faster With WebAssembly Components Bailey Hayes Director @Cosmonic 14:55 Dumbo / Navy Yard Session jvm Virtual Threads for Lightweight Concurrency and Other JVM Enhancements Ron Pressler Technical Lead OpenJDK's Project Loom @Oracle 16:10 Dumbo / Navy Yard Session Software Supply Chain Security Achieving SLSA Certification with a “Bring-Your-Own-Builder” Framework Asra Ali Software Engineer @Google 17:25 Dumbo / Navy Yard Session Software Supply Chain Security Securing the Software Supply Chain: How in-toto and TUF Work Together to Combat Supply Chain Attacks Marina Moore PhD Candidate @NYU & Tech Lead for CNCF's TAG Security