Skip to content
  • No due date Last updated 3 months ago

    A framework to bring / build your own builder, allowing existing tools / GitHub Actions to be safely wrapped into a SLSA level 3 reusable workflow.

  • No due date Last updated 10 months ago

    Add the ability to execute builds by running a Docker image and gen…

    Add the ability to execute builds by running a Docker image and generate provenance for the build.

    This will add a new container workflow which will allow projects to build artifacts using a docker image and generate provenance for SLSA Level 3.

    50% complete
  • No due date Last updated 10 months ago

    A builder to build and publish packages to Maven central, using the BYOB framework

  • No due date Last updated 10 months ago

    A SLSA compliant builder for https://bazel.build/ projects, using v1.0 specs

    57% complete
  • No due date Last updated 10 months ago

    Gradle Java builder, using BYOB framework

    75% complete
  • No due date Last updated 10 months ago
  • No due date Last updated 10 months ago

    This milestone tracks support for SLSA v1.0

    22% complete
  • No due date Last updated 10 months ago

    This milestone will add a new reusable workflow to build and publis…

    This milestone will add a new reusable workflow to build and publish Node.js npm packages with that means the provenance requirements
    for SLSA Level 3 by simply adding a new job to their existing GitHub Actions workflow.

    This will serve as the "Trusted Builder" for npm RFC-0049.

  • No due date Last updated 11 months ago

    Milestone for next release. Not particular features, mostly updates, fixes and improvements

    60% complete
  • No due date Last updated over 1 year ago

    A new reusable workflow will be developed (likely in another reposi…

    A new reusable workflow will be developed (likely in another repository) to build Docker images from a Dockerfile.

    This will add a new Dockerfile builder workflow which will allow OSS projects to generate provenance for their Docker images that satisfies the provenance requirements for SLSA Level 3.

    This workflow will use the BYOB framework.