-
-
Notifications
You must be signed in to change notification settings - Fork 130
Description
Current state: Still in initial review - but unlikely to be at Level 1.
- Node.js SLSA.dev Review
*Restricted to comment only, but if you'd like to be added as an editor just let me know.
Background:
Supply chain Levels for Software Artifacts, or SLSA (salsa).
It’s a security framework, a check-list of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure in your projects, businesses or enterprises. It’s how you get from safe enough to being as resilient as possible, at any link in the chain.
A few of us got together to start looking at the SLSA framework (@mhdawson, @richardlau, @sxa). The plan was to first audit where we believe we are today against the requirements, and then gradually pick a few of the sections to try and move us towards the next level. Any specific actions we agree to take would likely be spread across various working groups - I believe mostly the Build WG, Release WG, and Node.js core.
Edit: I figure I should explicitly mention that there's no expectation that the project will agree to implement all of the work to meet the higher level requirements. We may reach a point where a requirement could add too much work/maintenance to a particular group that we decide not to pursue it at that time.
Next steps:
- Collate all of the requirements we have queries on, and find contacts to help answer.
- List remaining steps towards Level 1.
- Pick which of the remaining Level 1 requirements are appropriate to try and meet in the near term.