Explore the challenges and insights gained from automating SLSA-compliance evaluation in this 42-minute conference talk by Daniel Nebenzahl from Scribe-security. Delve into the SLSA framework, focusing on provenance and evidence-based trust. Examine pipeline dynamics and the initial steps towards SLSA Level 1 compliance. Discover the complexities of log file management and the importance of immutable references. Learn about the automation process for SLSA Levels 1 and 2 evaluation, including source verification and retention requirements. Investigate the challenges of implementing SLSA Level 3, particularly regarding ephemeral environments and isolation. Witness a demonstration of untrusted logs and unfalsifiable provenance. Conclude with key takeaways on build parameterlessness, hermeticity, and the path to SLSA Level 4 compliance.
Lessons Learned from Automating SLSA-Compliance Evaluation