Search / openssf/osps-baseline-to-slsa / v0.0.0-dev-671f23f

Release · v0.0.0-dev-671f23f

openssf/osps-baseline-to-slsa Mapping Document

openssf/osps-baseline-to-slsa

Cross-walk from the Open Source Project Security (OSPS) Baseline controls to SLSA. Each mapping asserts a "relates-to" relationship; strength, confidence-level, and rationale are left unset and should be added as the mappings are individually reviewed.

Published by OSPS Baseline Authors

License No license declared

Install

OCI v1.1
$grcli unpack --repository openssf/osps-baseline-to-slsa --version v0.0.0-dev-671f23f

grcli unpack verifies this signature against the recorded identity below and fails closed before writing any files — no separate verify step needed. Pass --no-verify to skip.

Coordinate
oci.grc.store/openssf/osps-baseline-to-slsa:v0.0.0-dev-671f23f
Manifest digest
sha256:fa634e20ba109eddcc8341d1dcd162e9d4b80165c7255f8691c3634a68a29e9c
Signed by
no signature recorded

Identity recorded by this hub when the version was published; unpack (above) checks the signature against it.

Verify in CI — check the signature without downloading
$grcli verify --repository openssf/osps-baseline-to-slsa --version v0.0.0-dev-671f23f

Read-only: downloads nothing and exits non-zero if the signature or the recorded identity doesn't match — use it as an admission/policy gate.

Provenance

1 layer
Digest Media type Size
d473db9efd65… application/vnd.gemara.artifact.v1+yaml 3.0 KiB
Bundle config blob
{
  "bundle-version": "1.0",
  "gemara-version": "1.2.0",
  "metadata": {
    "provenance": {
      "buildDefinition": {
        "buildType": "https://grc.store/grcli/buildtype/v0",
        "externalParameters": {
          "artifact": {
            "id": "osps-baseline-to-slsa",
            "type": "MappingDocument"
          },
          "target": {
            "registry": "oci.grc.store",
            "repository": "openssf/osps-baseline-to-slsa",
            "tag": "v0.0.0-dev-671f23f"
          }
        },
        "internalParameters": {
          "CI": "true",
          "GITHUB_ACTIONS": "true",
          "GITHUB_ACTOR": "eddie-knight",
          "GITHUB_REF": "refs/heads/main",
          "GITHUB_REPOSITORY": "eddie-knight/security-baseline",
          "GITHUB_RUN_ATTEMPT": "1",
          "GITHUB_RUN_ID": "26617016306",
          "GITHUB_SHA": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
          "GITHUB_WORKFLOW": "Publish to grc.store",
          "RUNNER_OS": "Linux"
        },
        "resolvedDependencies": [
          {
            "name": "/home/runner/work/_temp/staged/osps-to-slsa.yaml",
            "uri": "file:///home/runner/work/_temp/staged/osps-to-slsa.yaml",
            "digest": {
              "sha256": "d473db9efd65aa7dcc0363ebd5be1f0e8be691e640c81177106a2aad82b21534"
            }
          },
          {
            "name": "source",
            "uri": "git+https://github.com/eddie-knight/security-baseline@671f23f015e4b0f6108ab8f82f0eba7f89d55dce",
            "digest": {
              "gitCommit": "671f23f015e4b0f6108ab8f82f0eba7f89d55dce"
            }
          }
        ]
      },
      "runDetails": {
        "builder": {
          "id": "https://github.com/eddie-knight/security-baseline/actions/runs/26617016306",
          "version": {
            "go": "go1.25.0",
            "go-arch": "amd64",
            "go-os": "linux",
            "grcli": "v0.2.2"
          }
        },
        "metadata": {
          "invocationId": "26617016306-1",
          "startedOn": "2026-05-29T03:57:20.603726446Z",
          "finishedOn": "2026-05-29T03:57:20.682909678Z"
        },
        "byproducts": [
          {
            "name": "osps-to-slsa.yaml",
            "digest": {
              "sha256": "d473db9efd65aa7dcc0363ebd5be1f0e8be691e640c81177106a2aad82b21534"
            }
          }
        ]
      }
    }
  },
  "artifacts": [
    {
      "name": "osps-to-slsa.yaml",
      "type": "MappingDocument",
      "id": "osps-baseline-to-slsa",
      "role": "artifact"
    }
  ]
}

No rich preview yet

This UI can't render MappingDocument artifacts richly yet. The raw content is shown below, and the artifact stays pullable via the coordinate above.

mappings:
  - id: M-OSPS-AC-04-SLSA
    relationship: relates-to
    source: OSPS-AC-04
    targets:
      - entry-id: Producer - Choose an appropriate build platform
      - entry-id: Build platform - Isolation strength - Isolated
  - id: M-OSPS-BR-01-SLSA
    relationship: relates-to
    source: OSPS-BR-01
    targets:
      - entry-id: Choose an appropriate build platform
  - id: M-OSPS-BR-02-SLSA
    relationship: relates-to
    source: OSPS-BR-02
    targets:
      - entry-id: Follow a consistent build process
      - entry-id: Provenance generation- Exists, Authentic
  - id: M-OSPS-BR-03-SLSA
    relationship: relates-to
    source: OSPS-BR-03
    targets:
      - entry-id: Choose an appropriate build platform
  - id: M-OSPS-BR-04-SLSA
    relationship: relates-to
    source: OSPS-BR-04
    targets:
      - entry-id: Choose an appropriate build platform
      - entry-id: Follow a consistent build process
      - entry-id: Build platform - Isolation strength - isolated
  - id: M-OSPS-BR-05-SLSA
    relationship: relates-to
    source: OSPS-BR-05
    targets:
      - entry-id: Isolation strength - isolated
  - id: M-OSPS-BR-06-SLSA
    relationship: relates-to
    source: OSPS-BR-06
    targets:
      - entry-id: Distribute provenance - Exists
  - id: M-OSPS-QA-01-SLSA
    relationship: relates-to
    source: OSPS-QA-01
    targets:
      - entry-id: Build platform - isolation strength - Isolated
  - id: M-OSPS-QA-04-SLSA
    relationship: relates-to
    source: OSPS-QA-04
    targets:
      - entry-id: Build platform - isolation strength - Isolated
metadata:
  author:
    id: openssf
    name: OSPS Baseline Authors
    type: Human
  description: |
    Cross-walk from the Open Source Project Security (OSPS) Baseline
    controls to SLSA. Each mapping asserts a "relates-to"
    relationship; strength, confidence-level, and rationale are left
    unset and should be added as the mappings are individually
    reviewed.
  draft: true
  gemara-version: 1.2.0
  id: osps-baseline-to-slsa
  mapping-references:
    - description: |
        The Open Source Project Security (OSPS) Baseline is a set of security
        criteria that projects should meet to demonstrate a strong security
        posture.
      id: osps-baseline
      title: Open Source Project Security Baseline
      url: https://github.com/ossf/security-baseline
      version: draft
    - description: SLSA (pronounced "salsa") is a security framework from source to
        service, giving anyone working with software a common language for
        increasing levels of software security and supply chain integrity. It’s
        how you get from safe enough to being as resilient as possible, at any
        link in the chain.
      id: SLSA
      title: Supply Chain Levels for Software Artifacts
      url: https://github.com/slsa-framework/slsa
      version: "1.0"
  type: MappingDocument
  version: v0.0.0-dev-671f23f
source-reference:
  entry-type: Control
  reference-id: osps-baseline
target-reference:
  entry-type: Guideline
  reference-id: SLSA
title: OSPS Baseline to SLSA Mapping