Revalidated public source record

Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2

Source scope

Current approved software supply-chain integrity specification at the 2026-08-14 research cutoff, relevant to attributable releases and provenance.

Publisher, edition, and currentness

Source identity and K03 revalidation
PublisherOpenSSF
Claim statusCURRENT TECHNICAL STANDARD
Version or editionSLSA v1.2
Publication statusApproved
Publication dateUNAVAILABLE
Official locationhttps://slsa.dev/spec/v1.2/
K03 revalidated2026-08-14T22:04:09Z
Currentness assessmentThe official SLSA site identifies Version 1.2 as the current approved specification at K03 revalidation; the page does not expose a precise publication date in the reviewed content.
Superseded byNo successor is assigned in the current source catalog.

Claim-level support

Each row records the precise proposition this corpus draws from an official section. The citation does not authorize broader conclusions than the stated proposition.

Exact sections and supported propositions
SectionProposition supported in this corpusOfficial location
Specification statusSLSA v1.2 is an approved specification for incrementally improving software supply-chain security.Official section
Build requirementsSLSA levels and provenance requirements qualify build evidence; they do not prove that a deployed service is currently operating.Official section

How this source may be used

  • Confirm that the official edition, jurisdiction, and status remain current before high-stakes reliance.
  • Cite the exact section supporting the proposition rather than the publication title alone.
  • Keep technical conformance separate from factual truth, legal authority, moral status, and institutional operation.
  • Record retrieval, correction, supersession, and purpose qualification.

Limitations

An official source can still be irrelevant, incomplete, stale, disputed, or unsuitable for a named decision. A standard can define an interchange or security mechanism without resolving personhood, citizenship, sovereignty, consciousness, consent, legal competence, or factual truth. A statute can regulate systems without recognizing Machine Intelligence as a legal person.

The official SLSA site identifies Version 1.2 as the current approved specification at K03 revalidation; the page does not expose a precise publication date in the reviewed content.

Corrections, contradictions, and supersession

Where this source is used

Authority boundary

Publication by OpenSSF establishes source provenance and official status within the publisher’s scope. It does not transfer governance, registry, assurance, or legal authority to ᚲ.com. The source remains external; this page is a knowledge record and revalidation log.

Exact source-section claims

Each proposition has a stable ID, status, scope, owning route, evidence relationship, currentness qualification, correction state, and synchronized JSON record. Record completeness does not make the proposition true.

Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2 — Specification status

SLSA v1.2 is an approved specification for incrementally improving software supply-chain security.

Qualification: Official publication and exact-section support do not transfer authority beyond the source's scope or prove every external fact.

Support relationship

Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2 — Build requirements

SLSA levels and provenance requirements qualify build evidence; they do not prove that a deployed service is currently operating.

Qualification: Official publication and exact-section support do not transfer authority beyond the source's scope or prove every external fact.

Support relationship