slsa icon indicating copy to clipboard operation
slsa copied to clipboard

blog: supply chain robots, electric sheep, and SLSA

Open xbcsmith opened this issue 1 month ago • 3 comments

A blog post based on a talk given at ATO 2025 on Supply Chain Security and SLSA

A talk about creating automation, shifting left, attack vectors, attestations, verification, zero-trust, and SLSA.

In the talk I cover creating automation, shifting left, attack vectors, attestations, verification, zero-trust, and how the SLSA spec helps implement solutions for each. The main take away is that security needs to be applied everywhere in the pipeline. The talk should lead to a greater discussion around the challenges of securing the supply chain, supporting EO 14028 and ISO27001, and improving the security posture of your pipelines.

Talk Link

xbcsmith avatar Dec 03 '25 15:12 xbcsmith

Deploy Preview for slsa ready!

Name Link
Latest commit 4f0b4f1543d977e12f488ebbf0cae3d454f8e303
Latest deploy log https://app.netlify.com/projects/slsa/deploys/694021ff263944000825c7f0
Deploy Preview https://deploy-preview-1528--slsa.netlify.app
Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

netlify[bot] avatar Dec 03 '25 15:12 netlify[bot]

Thanks for this blog proposal. Did you use voice-to-text? It reads exactly like you talk.

I left a couple of comments to try to help with clarity.

Didn't use voice-to-text just banged it out on the keyboard like the old days...

xbcsmith avatar Dec 04 '25 23:12 xbcsmith

According to CONTRIBUTING, we need another maintainer to approve: https://github.com/slsa-framework/slsa/blob/main/CONTRIBUTING.md#pull-request-types

@TomHennen , would you mind looking at this?

arewm avatar Dec 12 '25 16:12 arewm