Supply Chain Security for Software Artefacts: SBOMs, Provenance Attestation, and SLSA Compliance in CI/CD
Abstract
High-profile software supply chain attacks have elevated SBOM generation, provenance attestation, and SLSA framework compliance to regulatory priority. This paper presents a comprehensive implementation and evaluation of a supply chain security pipeline integrating Syft, in-toto, and SLSA build provenance across 16 open-source and enterprise projects. We measure attestation overhead, SLSA level attainability, and false-positive rates for dependency vulnerability matching. Full SLSA Level 3 compliance was achieved with less than 4% pipeline overhead. We identify toolchain gaps, particularly around hermetic build reproducibility, and propose a pragmatic SLSA adoption roadmap calibrated to team maturity and risk profile.
Cite this article
(2023). Supply Chain Security for Software Artefacts: SBOMs, Provenance Attestation, and SLSA Compliance in CI/CD. Research Explorations in Global Knowledge & Technology (REGKT), 3 (2). Retrieved from https://regkt.com/article.php?id=859&slug=supply-chain-security-software-artefacts-sbom-provenance-slsa-compliance-cicd