SLSA – Supply-Chain Levels for Software Artifacts
slsa.dev
slsa.dev
Bad idea. We should instead have 1000's of people around the world continuously reproducing builds of software, and continuously verifying amongst each other that everyone is building and then using the same peer reviewed version of software.[2] In this way, an attacker is forced to reveal their attack to everyone and can't just compromise the "secure build platforms" and conduct selective attacks.
I highly appreciate the idea of reproducibility. It is one of the ways to provide (and verify) integrity. And unfortunately, this is not widely adopted and in some cases even difficult to achieve…
And future directions[0] include Source track that is supposed to to prevent a single compromised actor or account from introducing malicious changes.