Skip to content

Node.js core SLSA.dev Review #876

@BethGriggs

Description

@BethGriggs

Current state: Still in initial review - but unlikely to be at Level 1.

  • Node.js SLSA.dev Review
    *Restricted to comment only, but if you'd like to be added as an editor just let me know.

Background:

Supply chain Levels for Software Artifacts, or SLSA (salsa).

It’s a security framework, a check-list of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure in your projects, businesses or enterprises. It’s how you get from safe enough to being as resilient as possible, at any link in the chain.

A few of us got together to start looking at the SLSA framework (@mhdawson, @richardlau, @sxa). The plan was to first audit where we believe we are today against the requirements, and then gradually pick a few of the sections to try and move us towards the next level. Any specific actions we agree to take would likely be spread across various working groups - I believe mostly the Build WG, Release WG, and Node.js core.

Edit: I figure I should explicitly mention that there's no expectation that the project will agree to implement all of the work to meet the higher level requirements. We may reach a point where a requirement could add too much work/maintenance to a particular group that we decide not to pursue it at that time.


Next steps:

  • Collate all of the requirements we have queries on, and find contacts to help answer.
  • List remaining steps towards Level 1.
  • Pick which of the remaining Level 1 requirements are appropriate to try and meet in the near term.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions