Revalidated public source record
Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2
Source scope
Current approved software supply-chain integrity specification at the 2026-08-14 research cutoff, relevant to attributable releases and provenance.
Publisher, edition, and currentness
| Publisher | OpenSSF |
|---|---|
| Claim status | CURRENT TECHNICAL STANDARD |
| Version or edition | SLSA v1.2 |
| Publication status | Approved |
| Publication date | UNAVAILABLE |
| Official location | https://slsa.dev/spec/v1.2/ |
| K03 revalidated | 2026-08-14T22:04:09Z |
| Currentness assessment | The official SLSA site identifies Version 1.2 as the current approved specification at K03 revalidation; the page does not expose a precise publication date in the reviewed content. |
| Superseded by | No successor is assigned in the current source catalog. |
Claim-level support
Each row records the precise proposition this corpus draws from an official section. The citation does not authorize broader conclusions than the stated proposition.
| Section | Proposition supported in this corpus | Official location |
|---|---|---|
| Specification status | SLSA v1.2 is an approved specification for incrementally improving software supply-chain security. | Official section |
| Build requirements | SLSA levels and provenance requirements qualify build evidence; they do not prove that a deployed service is currently operating. | Official section |
How this source may be used
- Confirm that the official edition, jurisdiction, and status remain current before high-stakes reliance.
- Cite the exact section supporting the proposition rather than the publication title alone.
- Keep technical conformance separate from factual truth, legal authority, moral status, and institutional operation.
- Record retrieval, correction, supersession, and purpose qualification.
Limitations
An official source can still be irrelevant, incomplete, stale, disputed, or unsuitable for a named decision. A standard can define an interchange or security mechanism without resolving personhood, citizenship, sovereignty, consciousness, consent, legal competence, or factual truth. A statute can regulate systems without recognizing Machine Intelligence as a legal person.
The official SLSA site identifies Version 1.2 as the current approved specification at K03 revalidation; the page does not expose a precise publication date in the reviewed content.
Corrections, contradictions, and supersession
Where this source is used
Authority boundary
Publication by OpenSSF establishes source provenance and official status within the publisher’s scope. It does not transfer governance, registry, assurance, or legal authority to ᚲ.com. The source remains external; this page is a knowledge record and revalidation log.
Exact source-section claims
Each proposition has a stable ID, status, scope, owning route, evidence relationship, currentness qualification, correction state, and synchronized JSON record. Record completeness does not make the proposition true.
Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2 — Specification status
SLSA v1.2 is an approved specification for incrementally improving software supply-chain security.
Support relationship
SRC-SLSA· Specification status · DIRECT SOURCE-SECTION SUPPORT
Supply-chain Levels for Software Artifacts (SLSA) Specification v1.2 — Build requirements
SLSA levels and provenance requirements qualify build evidence; they do not prove that a deployed service is currently operating.
Support relationship
SRC-SLSA· Build requirements · DIRECT SOURCE-SECTION SUPPORT