Search / openssf/osps-baseline-to-slsa
mapping
OSPS Baseline to SLSA Mapping Mapping Document
openssf/osps-baseline-to-slsa
Cross-walk from the Open Source Project Security (OSPS) Baseline controls to SLSA. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.
Published by OSPS Baseline Authors
License No license declared
Pull latest (v0.0.0-dev-671f23f)
$grcli unpack --repository openssf/osps-baseline-to-slsa --version v0.0.0-dev-671f23f Releases
1 live| Version | Manifest digest | Published | License | Status | |
|---|---|---|---|---|---|
| v0.0.0-dev-671f23f | fa634e20ba109e… | 1mo ago | No license declared | Live unsigned | Details → |
Mapping references
external standards this artifact maps to (v0.0.0-dev-671f23f)-
The Open Source Project Security (OSPS) Baseline is a set of security criteria that projects should meet to demonstrate a strong security posture.
-
SLSA (pronounced "salsa") is a security framework from source to service, giving anyone working with software a common language for increasing levels of software security and supply chain integrity. It’s how you get from safe enough to being as resilient as possible, at any link in the chain.
Builds upon
artifacts this one extends, imports, or shares a lexicon withNo upstream references yet
This artifact doesn't extend, import, or share a lexicon with anything else in the registry.
Extended or imported by
other artifacts that build upon this oneNo dependents yet
Published artifacts that extend or import this one will appear here.