Supply Chain Security for Software Artefacts: SBOMs, Provenance Attestation, and SLSA Compliance in CI/CD

research-article
Received: Dec 5, 2022
Published: Jan 23, 2023
Authors:

Abstract

High-profile software supply chain attacks have elevated SBOM generation, provenance attestation, and SLSA framework compliance to regulatory priority. This paper presents a comprehensive implementation and evaluation of a supply chain security pipeline integrating Syft, in-toto, and SLSA build provenance across 16 open-source and enterprise projects. We measure attestation overhead, SLSA level attainability, and false-positive rates for dependency vulnerability matching. Full SLSA Level 3 compliance was achieved with less than 4% pipeline overhead. We identify toolchain gaps, particularly around hermetic build reproducibility, and propose a pragmatic SLSA adoption roadmap calibrated to team maturity and risk profile.

⬇ Download

Cite this article

(2023). Supply Chain Security for Software Artefacts: SBOMs, Provenance Attestation, and SLSA Compliance in CI/CD. Research Explorations in Global Knowledge & Technology (REGKT), 3 (2). Retrieved from https://regkt.com/article.php?id=859&slug=supply-chain-security-software-artefacts-sbom-provenance-slsa-compliance-cicd

Premium Membership Required

You need a premium account to view or download this article.

Become Premium