{"id":97693,"date":"2024-09-05T12:37:02","date_gmt":"2024-09-05T12:37:02","guid":{"rendered":"https:\/\/staging.checkmarx.com\/?post_type=glossary&#038;p=97693"},"modified":"2026-04-23T16:58:35","modified_gmt":"2026-04-23T14:58:35","slug":"what-is-the-slsa-framework","status":"publish","type":"glossary","link":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/","title":{"rendered":"SLSA Explained &#8211; Framework, Levels and Implementation Best Practices"},"content":{"rendered":"<p><em>Updated: 19\/04\/2026<\/em><\/p>\n\n\n<section class=\"section-article-tldr\">\n            <div class=\"acf-innerblocks-container\">\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-1\">Summary<\/h2>\n\n\n\n<p>SLSA, short for <strong>Supply-chain Levels for Software Artifacts<\/strong>, is a software supply chain security framework designed to improve build integrity, provenance, and trust in software artifacts. Maintained as an OpenSSF project, it gives organizations a practical, incrementally adoptable way to strengthen software supply chain security and prepare for growing customer, regulatory, and compliance expectations.<\/p>\n\n<\/div>\n        <\/section>\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-2\">What Is SLSA?<\/h2>\n\n\n\n<p>SLSA, pronounced \u201csalsa,\u201d stands for <strong>Supply-chain Levels for Software Artifacts<\/strong>. It is a set of incrementally adoptable guidelines for software supply chain security that helps organizations strengthen the integrity of software artifacts and reduce the risk of tampering during software development and delivery. SLSA is maintained as a project of the <strong>Open Source Security Foundation (<a href=\"https:\/\/openssf.org\/projects\/slsa\/\" type=\"link\" id=\"https:\/\/openssf.org\/projects\/slsa\/\">OpenSSF<\/a>)<\/strong> and developed through industry consensus, which is one reason it has become an important common language for software supply chain assurance.<\/p>\n\n\n\n<p>At a practical level, SLSA helps software producers and software consumers evaluate how software is built, where it comes from, and how much trust they can place in the resulting artifacts. Rather than treating software supply chain security as an abstract goal, it turns it into a more structured and measurable path for improvement.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-3\">SLSA Compliance and Future-proofing snapshot<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\">\n<thead><tr>\n<th>Requirement \/ Framework<\/th>\n<th>Industry<\/th>\n<th>Geo<\/th>\n<th>Due date<\/th>\n<th>One-sentence summary<\/th>\n<\/tr><\/thead>\n<tbody>\n<tr>\n<td><strong>EO 14028 \/ NIST SSDF guidance<\/strong><\/td>\n<td>Software vendors selling to the U.S. federal ecosystem; broadly relevant to software producers<\/td>\n<td>U.S.<\/td>\n<td>\n<strong>May 12, 2021<\/strong> for EO 14028; <strong>Feb 4, 2022<\/strong> for NIST Section 4e guidance<\/td>\n<td>U.S. federal software supply chain expectations pushed vendors toward stronger secure development, testing, and software integrity practices, and SLSA can help measure progress toward SSDF-aligned maturity. (<a href=\"https:\/\/www.nist.gov\/itl\/software-supply-chain-executive-order?utm_source=chatgpt.com\">NIST<\/a>)<\/td>\n<\/tr>\n<tr>\n<td><strong>FDA section 524B cyber-device requirements<\/strong><\/td>\n<td>Medical device manufacturers and cyber-device submitters<\/td>\n<td>U.S.<\/td>\n<td><strong>March 29, 2023<\/strong><\/td>\n<td>Applicable FDA premarket submissions for cyber devices must include cybersecurity information, including an SBOM, making software component visibility and supply chain trust especially important. (<a href=\"https:\/\/www.fda.gov\/medical-devices\/digital-health-center-excellence\/cybersecurity-medical-devices-frequently-asked-questions-faqs?utm_source=chatgpt.com\">U.S. Food and Drug Administration<\/a>)<\/td>\n<\/tr>\n<tr>\n<td><strong>NIS2<\/strong><\/td>\n<td>Critical infrastructure, digital services, cloud, data centers, managed services, health, energy, transport, manufacturing, and more<\/td>\n<td>EU<\/td>\n<td><strong>October 17, 2024<\/strong><\/td>\n<td>NIS2 raised the baseline for cybersecurity risk management across critical and important entities, increasing pressure for stronger supply chain oversight and software assurance. (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/nis2-commission-implementing-regulation?utm_source=chatgpt.com\">Digital Strategy<\/a>)<\/td>\n<\/tr>\n<tr>\n<td><strong>DORA<\/strong><\/td>\n<td>Financial services and financial-sector ICT dependencies<\/td>\n<td>EU<\/td>\n<td><strong>January 17, 2025<\/strong><\/td>\n<td>DORA applies to the financial sector and strengthens operational resilience expectations, making software integrity, third-party risk, and supply chain discipline more operationally important. (<a href=\"https:\/\/eur-lex.europa.eu\/EN\/legal-content\/summary\/digital-operational-resilience-for-the-financial-sector.html?utm_source=chatgpt.com\">EUR-Lex<\/a>)<\/td>\n<\/tr>\n<tr>\n<td><strong>EU Cyber Resilience Act reporting requirements<\/strong><\/td>\n<td>Manufacturers of products with digital elements<\/td>\n<td>EU<\/td>\n<td><strong>September 11, 2026<\/strong><\/td>\n<td>CRA reporting obligations begin in September 2026, increasing the importance of secure development, vulnerability handling, and stronger traceability across software-producing organizations. (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-reporting?utm_source=chatgpt.com\">Digital Strategy<\/a>)<\/td>\n<\/tr>\n<\/tbody>\n<\/table><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Organizations that improve provenance, build integrity, dependency governance, and artifact trust today are typically better positioned for customer reviews, audits, procurement scrutiny, and future regulatory change. That is one reason SLSA is becoming more important even when it is not explicitly mandated.<\/p>\n\n\n\n<p><\/p>\n\n\n<section class=\"section-block-info light-theme\">\n    <div class=\"main-wrapper block-info__wrapper\">\n        <div class=\"block-info center\">\n\t\t\t\n\t\t\t<h2 class=\"section-title article-anchor\" id=\"article-anchor-4\">Benchmark Your AppSec Maturity<\/h2>\t\t\t<p class=\"section-description\">Assess your AppSec maturity in minutes with 12 questions. Identify gaps, prioritize improvements, and get a practical roadmap &#8211; including specialized assessments, such as for EU regulations like NIS2, DORA, and CRA.\r\n\r\n<\/p>\n\t\t\t<div class=\"actions\">\n\t\t\t\t        <a href=\"\/apma-appsec-maturity-methodology-assessment\/\" class=\"btn btn-2 btn-bg white demo\">Take Free Assessment Now <\/a>\n        \t\t\t\t\t\t\t<\/div>\n        <\/div>\n    <\/div>\n<\/section>\n\n\n<p><br><\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-5\">Why SLSA Matters<\/h2>\n\n\n\n<p>Modern software supply chains are exposed to a growing range of risks. Vulnerable dependencies, compromised build environments, <a href=\"https:\/\/checkmarx.com\/product\/malicious-packages\/\" type=\"page\" id=\"96984\">malicious packages<\/a>, tampered artifacts, and weak provenance can all undermine trust in the software organizations build or consume.<\/p>\n\n\n\n<p>SLSA matters because it helps organizations move from general awareness of software supply chain risk to a more practical and measurable security model. It gives teams a shared way to reason about trust, integrity, and build assurance, while also providing a roadmap for improving security over time.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">\n<br>The SLSA framework can help secure against these risks by providing:<\/h3>\n\n\n\n<p><strong>Compliance and Assurance<\/strong> \u2013 An organization that adopts SLSA can demonstrate to their customers and stakeholders that it is following rigorous security practices. This is increasingly important as expectations around software security continue to rise.<\/p>\n\n\n\n<p><strong>Prevention of Supply Chain Attacks<\/strong> \u2013 By adhering to SLSA levels, organizations can mitigate the risk of various types of <a href=\"https:\/\/checkmarx.com\/learn\/software-supply-chain-management\/what-is-software-supply-chain-security\/\">supply chain attacks<\/a>. This includes identifying and mitigating risks associated with third-party dependencies and the build environment, preventing tampering during the build and distribution processes, and ensuring the integrity of software components.<\/p>\n\n\n\n<p><strong>Standardization of Best Practices<\/strong> \u2013 SLSA provides a set of industry-standard best practices that organizations can adopt to secure their software supply chains. This standardization helps in creating a common understanding and approach towards <a href=\"https:\/\/checkmarx.com\/learn\/supply-chain-security\/software-supply-chain-security-guide\/\">supply chain security<\/a>. As more organizations adopt SLSA practices, the overall software ecosystem becomes more secure, making it more difficult for attackers to exploit supply chain vulnerabilities.<\/p>\n\n\n\n<p><strong>Incremental Security Improvements<\/strong> \u2013 SLSA defines a roadmap of four levels of security maturity, from Level 0 (basic security requirements) to Level 3 (high assurance). This allows organizations to progressively improve their security posture over time, aligning with their specific risk profiles and resource availability.<\/p>\n\n\n\n<p><strong>Incident Response<\/strong> \u2013 In the event of a supply chain attack, SLSA\u2019s emphasis on provenance and build integrity can aid in faster incident response and impact assessment.<\/p>\n\n\n\n<p><strong>Provenance and Transparency<\/strong> \u2013 One of the core tenets of SLSA is to ensure the provenance of software artifacts. This means having verifiable metadata about where software components come from, how they were built, and how they were distributed. This transparency builds trust and accountability in the software supply chain.<\/p>\n\n\n\n<p>For software producers, that means stronger build trust and clearer evidence of how software was created. For software consumers, it means better signals for deciding whether a package, image, or artifact should be trusted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-6\">How the SLSA Framework Works<\/h2>\n\n\n\n<p>SLSA works by defining progressively stronger expectations for <a href=\"https:\/\/checkmarx.com\/solutions\/software-supply-chain-security\/\">software supply chain security<\/a>. Its focus is on improving confidence in the integrity of the software production process.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Provenance<\/h3>\n\n\n\n<p>One of the most important concepts in SLSA is <strong>provenance<\/strong>. Provenance is the metadata that explains how an artifact was produced, including what source it came from, what build process created it, and what environment performed the build.<\/p>\n\n\n\n<p>Strong provenance helps teams verify integrity, investigate issues, and make better trust decisions about the software they use or distribute.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Build Integrity<\/h3>\n\n\n\n<p>SLSA also emphasizes protecting the build process itself. If the build environment can be tampered with, then even trusted source code can produce untrusted artifacts.<\/p>\n\n\n\n<p>That is why SLSA places importance on stronger build controls, more trustworthy build systems, and better verification of how software artifacts are generated.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Incremental Adoption<\/h3>\n\n\n\n<p>SLSA is designed to be adopted progressively. Organizations do not need to reach the highest level immediately. Instead, they can use the framework as a roadmap to improve software supply chain security step by step.<\/p>\n\n\n\n<p>That makes SLSA practical for teams at different stages of security maturity. OpenSSF explicitly positions SLSA as incrementally adoptable guidance rather than an all-at-once maturity hurdle.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-7\">SLSA Levels Explained<\/h2>\n\n\n\n<p>SLSA describes progressively stronger levels of assurance. The exact requirements can evolve over time, but the general principle remains consistent: each level adds stronger controls and greater confidence in the integrity of software artifacts.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SLSA defines four progressive levels, each with its own set of requirements. <\/h3>\n\n\n\n<p>Each level builds upon the previous one, adding more security and assurance.<\/p>\n\n\n\n<p><strong>Level 0: No protection (prior to adoption of SLSA)<\/strong><\/p>\n\n\n\n<p><strong>Level 1: Adding provenance<\/strong><\/p>\n\n\n\n<p>Provenance is added to provide information about the build process: how the artifact was built, the build platform and process, etc. This enables the software producer and its consumers to patch, debug and rebuild software, and helps prevent mistakes in the release process.<\/p>\n\n\n\n<p><strong>Level 2: Using a hosted build platform<\/strong><\/p>\n\n\n\n<p>The hosted platform runs on dedicated infrastructure and signs the provenance with a digital signature for authenticity. This helps prevent tampering, deters insider threats, and reduces the attack surface.<\/p>\n\n\n\n<p><strong>Level 3: Hardened builds<\/strong><\/p>\n\n\n\n<p>Using a hardened build platform with strong tamper protection. This requires changes to the build platform but prevents tampering, reduces the impact of compromised packages, and provides confidence in packages.<\/p>\n\n\n\n<p>With SLSA, AppSec teams and developers incorporate security practices into the enterprise\u2019s build processes, so they have more confidence in the supply chain software artifacts they consume. From a business perspective, companies that prioritize and implement SLSA\u2019s supply chain security practices can differentiate themselves in the market, providing an edge over competitors.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-8\">How to Start Implementing SLSA<\/h2>\n\n\n\n<p>For most teams, implementing SLSA begins with visibility and consistency.<\/p>\n\n\n\n<p>Start by documenting how software is built today, including the source repositories, build systems, artifact repositories, and dependency sources involved in the delivery process. From there, focus on improving provenance, reducing manual or untrusted build steps, and strengthening control over dependencies and build environments.<\/p>\n\n\n\n<p>Implementation should be practical and phased. Teams do not need to redesign the entire software pipeline at once. Instead, they should identify the highest-risk gaps first, then improve controls incrementally.<\/p>\n\n\n\n<p>A good starting point usually includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>documenting build workflows<\/li>\n\n\n\n<li>strengthening version control and branch protections<\/li>\n\n\n\n<li>improving dependency governance<\/li>\n\n\n\n<li>introducing artifact signing and provenance where possible<\/li>\n\n\n\n<li>tightening CI\/CD security controls<\/li>\n\n\n\n<li>reducing the use of unverified or risky third-party components<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-9\">Best Practices for Using SLSA in Software Supply Chain Security<\/h2>\n\n\n\n<p>Implementing the SLSA framework effectively requires adherence to best practices that align with the framework\u2019s requirements and goals. <\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"535\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/01\/Checkmarx-Approach-to-Software-Supply-Chain-Security-1024x535.jpg\" alt=\"Approach to Software Supply Chain Security\" class=\"wp-image-89876\" srcset=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/01\/Checkmarx-Approach-to-Software-Supply-Chain-Security-1024x535.jpg 1024w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/01\/Checkmarx-Approach-to-Software-Supply-Chain-Security-300x157.jpg 300w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/01\/Checkmarx-Approach-to-Software-Supply-Chain-Security-768x401.jpg 768w, https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/01\/Checkmarx-Approach-to-Software-Supply-Chain-Security.jpg 1517w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">Checkmarx <a href=\"https:\/\/checkmarx.com\/blog\/checkmarx-approach-to-software-supply-chain-security\/\">Approach to Software Supply Chain Security<\/a><\/figcaption><\/figure>\n\n\n\n<p>Since SLSA is evolving and attempts to remain a framework and not a guide, this list is constantly evolving and should be accompanied with research of additional practices required for your security needs.<\/p>\n\n\n\n<p><strong>Here are some best practices for using SLSA in software supply chain security:<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Provide regular training for developers on secure coding practices, SLSA requirements, and the importance of software supply chain security.<\/li>\n\n\n\n<li>Use a robust version control system like Git. Ensure all changes are tracked, and the history is immutable.<\/li>\n\n\n\n<li>Require developers to sign their commits to verify the authenticity of code changes.<\/li>\n\n\n\n<li>Implement branch protection rules to prevent unauthorized changes, such as requiring pull requests for all changes and enforcing code reviews.<\/li>\n\n\n\n<li>Use isolated and ephemeral build environments to ensure that each build is independent and cannot be influenced by previous builds or external factors.<\/li>\n\n\n\n<li>Prevent<a href=\"https:\/\/checkmarx.com\/blog\/how-to-prevent-secrets-from-leaking-out-of-your-dev-pipeline\/\"> secret credentials<\/a> and other sensitive information from being included in files or repositories where they might be exposed.<\/li>\n\n\n\n<li>Aim for reproducible builds, where the same source code always produces the same binary. This helps detect tampering and inconsistencies.<\/li>\n\n\n\n<li>Use vetted and controlled dependencies, and ensure they come from trusted sources. Scan with<a href=\"https:\/\/checkmarx.com\/learn\/sca\/types-of-sca-tools\/\"> SCA tools<\/a> and regularly update dependencies to patch vulnerabilities.<\/li>\n\n\n\n<li>Automatically generate detailed provenance metadata for each build, including information about the source code, build environment, and dependencies. You can use an automated<a href=\"https:\/\/checkmarx.com\/product\/sbom\/\"> SBOM solution<\/a> for this.<\/li>\n\n\n\n<li>Sign all provenance metadata and build artifacts using cryptographic keys. Ensure these keys are securely managed and rotated regularly.<\/li>\n\n\n\n<li>Store provenance metadata in a secure, immutable, and accessible manner, such as in a blockchain or trusted database.<\/li>\n\n\n\n<li>Conduct regular security scans and audits of your build and supply chain processes to detect vulnerabilities and malicious packages and ensure compliance with SLSA requirements.<\/li>\n\n\n\n<li>Have a clear incident response plan in place for handling supply chain security incidents, including steps for containment, investigation, and remediation.<\/li>\n\n\n\n<li>Integrate SLSA best practices into your CI\/CD pipelines to automate compliance and reduce manual errors.<\/li>\n\n\n\n<li>Use security tools that support SLSA practices, such as those for static analysis, dependency scanning, and secret management.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-10\">SLSA, Compliance, and Future-Proofing<\/h2>\n\n\n\n<p>SLSA is not a compliance regime by itself, but it is increasingly useful for organizations that need to show stronger software supply chain discipline. OpenSSF explicitly notes that SLSA can help organizations measure efforts toward compliance with the <strong>NIST Secure Software Development Framework (SSDF)<\/strong>. That matters because SSDF-aligned practices are part of the broader U.S. federal software supply chain push that followed <strong>Executive Order 14028<\/strong>.<\/p>\n\n\n\n<p>It is especially relevant for industries and organizations that face higher expectations around software integrity, traceability, and secure development practices, including:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>government and defense contractors<\/strong><\/li>\n\n\n\n<li><strong>regulated healthcare and medical device manufacturers<\/strong><\/li>\n\n\n\n<li><strong>financial services<\/strong><\/li>\n\n\n\n<li><strong>critical infrastructure and industrial technology<\/strong><\/li>\n\n\n\n<li><strong>enterprise software vendors selling into regulated or security-sensitive markets<\/strong><\/li>\n<\/ul>\n\n\n\n<p>Several current and emerging requirements make this more urgent:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">U.S. federal software supply chain expectations<\/h3>\n\n\n\n<p><a href=\"https:\/\/www.nist.gov\/itl\/executive-order-14028-improving-nations-cybersecurity\">Executive Order 14028 <\/a>pushed U.S. agencies and standards bodies to strengthen software supply chain security guidance, including the use of SSDF-aligned practices. SLSA is useful here because it provides practical ways to strengthen build trust, provenance, and artifact integrity.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">EU Cyber Resilience Act<\/h3>\n\n\n\n<p>The <a href=\"https:\/\/checkmarx.com\/blog\/preparing-for-europes-most-extensive-cybersecurity-directive-nis2-what-appsec-teams-need-to-know\/\" type=\"post\" id=\"90079\">EU Cyber Resilience Act<\/a> raises expectations for products with digital elements, including vulnerability handling and reporting. <\/p>\n\n\n\n<p>The European Commission states that manufacturers must begin reporting actively exploited vulnerabilities and severe incidents starting <strong>11 September 2026<\/strong>, which makes stronger supply chain discipline and traceability increasingly important.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">NIS2<\/h3>\n\n\n\n<p>NIS2 has already raised the baseline for cybersecurity risk management and supply chain considerations across essential and important entities in the EU. <\/p>\n\n\n\n<p>The directive required Member States to transpose it by <strong>17 October 2024<\/strong>, making software supply chain security and vendor governance more operationally relevant for affected organizations.<\/p>\n\n\n<section class=\"section-block-info light-theme\">\n    <div class=\"main-wrapper block-info__wrapper\">\n        <div class=\"block-info center\">\n\t\t\t        <img decoding=\"async\" class=\"block-info__img-bg\" src=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2025\/05\/apma-hero-bg-scaled.webp\" width=\"1440\" height=\"530\" alt=\"apma-hero-bg\" loading=\"lazy\">\n        \n\t\t\t<h2 class=\"section-title article-anchor\" id=\"article-anchor-11\">Are you NIS2, DORA and CRA Proof?<\/h2>\t\t\t<p class=\"section-description\">Self-assess your AppSec maturity in minutes with 12 questions. \r\nIdentify gaps, prioritize improvements, and get a practical roadmap \u2013 including specialized assessments, such as for EU regulations like NIS2, DORA, and CRA.<\/p>\n\t\t\t<div class=\"actions\">\n\t\t\t\t        <a href=\"https:\/\/checkmarx.com\/apma-appsec-maturity-methodology-assessment\/\" class=\"btn btn-2 btn-bg white demo\">Start the Assessment<\/a>\n        \t\t\t\t\t\t\t<\/div>\n        <\/div>\n    <\/div>\n<\/section>\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">FDA cyber-device requirements<\/h3>\n\n\n\n<p>For applicable cyber devices, FDA section 524B requirements have applied to relevant premarket submissions since <strong>29 March 2023<\/strong>, including expectations around postmarket vulnerability management and a <strong><a href=\"https:\/\/checkmarx.com\/product\/sbom\/\" type=\"page\" id=\"667\">software bill of materials (SBOM)<\/a><\/strong>. For medical device manufacturers, this makes software component visibility and supply chain trust highly relevant.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Why this matters for future-proofing<\/h3>\n\n\n\n<p>Even where SLSA is not explicitly mandated, the direction of travel is clear: buyers, regulators, and enterprise customers increasingly expect stronger evidence that software is built in a trustworthy way. Adopting SLSA-aligned practices now can help organizations:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>improve readiness for customer security reviews<\/li>\n\n\n\n<li>support vendor and procurement questionnaires<\/li>\n\n\n\n<li>strengthen regulated-product submissions<\/li>\n\n\n\n<li>reduce future compliance friction<\/li>\n\n\n\n<li>create stronger evidence of secure software development practices<\/li>\n<\/ul>\n\n\n\n<p>In that sense, SLSA is not only a security framework. It is also a practical way to future-proof software delivery processes against rising trust and assurance expectations.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-12\">Who Owns SLSA in the SDLC?<\/h2>\n\n\n\n<p>SLSA is a shared responsibility that involves executive leadership, security teams, development teams, QA, operations, and compliance professionals. <\/p>\n\n\n\n<p>By working together and adhering to the SLSA framework, organizations can significantly enhance the security and integrity of their software supply chains.<\/p>\n\n\n\n<p><strong>Executive Leadership \u2013 CISO, CTO, CIO<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Set strategic goals for software supply chain security.<\/li>\n\n\n\n<li>Allocate resources and budgets for implementing SLSA.<\/li>\n\n\n\n<li>Ensure organization-wide adherence to security policies and frameworks.<\/li>\n<\/ul>\n\n\n\n<p><strong>Security Team <\/strong><strong>\u2013<\/strong><strong> Security Architects, Security Engineers, Compliance Officers<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Develop and enforce security policies and best practices related to SLSA.<\/li>\n\n\n\n<li>Conduct threat modeling and risk assessments.<\/li>\n\n\n\n<li>Implement security controls and monitoring solutions.<\/li>\n\n\n\n<li>Ensure compliance with relevant regulations and standards (e.g., GDPR, HIPAA, NIST).<\/li>\n<\/ul>\n\n\n\n<p><strong>Engineering Team <\/strong><strong>\u2013<\/strong><strong> Developers, DevOps, QA<\/strong><\/p>\n\n\n\n<p>Monitor and respond to security incidents related to the software supply chain.n that builds, distributes, or depends on modern software can benefit from the framework.<\/p>\n\n\n\n<p>Integrate SLSA practices into the CI\/CD pipeline.<\/p>\n\n\n\n<p>Ensure secure coding practices and proper dependency management.<\/p>\n\n\n\n<p>Maintain the integrity of the build environment and tooling.<\/p>\n\n\n\n<p>Perform security testing, including static and dynamic analysis.<\/p>\n\n\n\n<p>Manage the infrastructure and environments where software is built, tested, and deployed.<\/p>\n\n\n\n<p>Ensure secure configurations and patch management.<\/p>\n\n\n\n<h2 class=\"wp-block-heading article-anchor\" id=\"article-anchor-13\">How Checkmarx Supports SLSA and Software Supply Chain Security<\/h2>\n\n\n\n<p>SLSA is most useful when it is supported by practical controls across the software supply chain. Checkmarx helps organizations strengthen software supply chain security through capabilities that support dependency governance, malicious package detection, secrets detection, policy enforcement, and risk prioritization across modern development workflows. These capabilities are designed to improve visibility into open-source usage, repository hygiene, package trust, and build-related risk while fitting naturally into IDEs, CI\/CD pipelines, and governance workflows.<\/p>\n\n\n\n<p>That matters because SLSA depends on operational discipline, not just conceptual alignment. Teams need practical ways to assess dependencies, block malicious packages, enforce policies, and improve trust across software delivery workflows. Checkmarx supports that by connecting supply chain signals into a broader application security context and helping teams act on them earlier and with more consistency.<\/p>\n\n\n\n<section class=\"section-accordion\">\n    <div class=\"main-wrapper section-accordion__wrapper\">\n        <h2 class=\"section-title article-anchor\" id=\"article-anchor-14\">FAQ: SLSA<\/h2>\n        <div class=\"fag-accordion__wrapper\">\n            <div class=\"js-accordion fag-accordion\">\n                <div>\n\n                                            <div class=\"js-accordion__item fag-accordion__item \">\n                            <h3 class=\"js-accordion__btn fag-accordion__btn\">\n                                <svg width=\"34px\" height=\"23px\" viewbox=\"0 0 34 23\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                                    <g id=\"Page-1\" stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\">\n                                        <g id=\"Shape\" transform=\"translate(0.939453, 1.530000)\" stroke-width=\"3\">\n                                            <path d=\"M19.810947,20.4179 L31.029947,9.14 M30.029947,10.1989 L0,10.1989 M31.029947,11.26 L19.810947,0\"><\/path>\n                                        <\/g>\n                                    <\/g>\n                                <\/svg>\n                                What is SLSA?                            <\/h3>\n                            <div class=\"js-accordion-content fag-accordion__content\">\n                                <p>SLSA is a software supply chain security framework that helps organizations improve build integrity, provenance, and trust in software artifacts. It stands for Supply-chain Levels for Software Artifacts.<\/p>\n                            <\/div>\n                        <\/div>\n                                                <div class=\"js-accordion__item fag-accordion__item \">\n                            <h3 class=\"js-accordion__btn fag-accordion__btn\">\n                                <svg width=\"34px\" height=\"23px\" viewbox=\"0 0 34 23\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                                    <g id=\"Page-1\" stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\">\n                                        <g id=\"Shape\" transform=\"translate(0.939453, 1.530000)\" stroke-width=\"3\">\n                                            <path d=\"M19.810947,20.4179 L31.029947,9.14 M30.029947,10.1989 L0,10.1989 M31.029947,11.26 L19.810947,0\"><\/path>\n                                        <\/g>\n                                    <\/g>\n                                <\/svg>\n                                Who maintains SLSA?                            <\/h3>\n                            <div class=\"js-accordion-content fag-accordion__content\">\n                                <p>SLSA is maintained as a project of the Open Source Security Foundation, or OpenSSF, and developed through industry consensus.<\/p>\n                            <\/div>\n                        <\/div>\n                                                <div class=\"js-accordion__item fag-accordion__item \">\n                            <h3 class=\"js-accordion__btn fag-accordion__btn\">\n                                <svg width=\"34px\" height=\"23px\" viewbox=\"0 0 34 23\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                                    <g id=\"Page-1\" stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\">\n                                        <g id=\"Shape\" transform=\"translate(0.939453, 1.530000)\" stroke-width=\"3\">\n                                            <path d=\"M19.810947,20.4179 L31.029947,9.14 M30.029947,10.1989 L0,10.1989 M31.029947,11.26 L19.810947,0\"><\/path>\n                                        <\/g>\n                                    <\/g>\n                                <\/svg>\n                                What does SLSA help prevent?                            <\/h3>\n                            <div class=\"js-accordion-content fag-accordion__content\">\n                                <p>SLSA helps organizations reduce the risk of tampering, compromised build processes, and other software supply chain attacks by strengthening trust in how software is built and delivered.<\/p>\n                            <\/div>\n                        <\/div>\n                        <\/div>\n<div>                        <div class=\"js-accordion__item fag-accordion__item \">\n                            <h3 class=\"js-accordion__btn fag-accordion__btn\">\n                                <svg width=\"34px\" height=\"23px\" viewbox=\"0 0 34 23\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                                    <g id=\"Page-1\" stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\">\n                                        <g id=\"Shape\" transform=\"translate(0.939453, 1.530000)\" stroke-width=\"3\">\n                                            <path d=\"M19.810947,20.4179 L31.029947,9.14 M30.029947,10.1989 L0,10.1989 M31.029947,11.26 L19.810947,0\"><\/path>\n                                        <\/g>\n                                    <\/g>\n                                <\/svg>\n                                What is provenance in SLSA?                            <\/h3>\n                            <div class=\"js-accordion-content fag-accordion__content\">\n                                <p data-start=\"16951\" data-end=\"17102\">In SLSA, provenance is the metadata that describes where an artifact came from and how it was built. It is a key part of verifying integrity and trust.<\/p>\n<h3 data-section-id=\"w42xg4\" data-start=\"17104\" data-end=\"17138\"><\/h3>\n                            <\/div>\n                        <\/div>\n                                                <div class=\"js-accordion__item fag-accordion__item \">\n                            <h3 class=\"js-accordion__btn fag-accordion__btn\">\n                                <svg width=\"34px\" height=\"23px\" viewbox=\"0 0 34 23\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                                    <g id=\"Page-1\" stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\">\n                                        <g id=\"Shape\" transform=\"translate(0.939453, 1.530000)\" stroke-width=\"3\">\n                                            <path d=\"M19.810947,20.4179 L31.029947,9.14 M30.029947,10.1989 L0,10.1989 M31.029947,11.26 L19.810947,0\"><\/path>\n                                        <\/g>\n                                    <\/g>\n                                <\/svg>\n                                Is SLSA useful for compliance?                            <\/h3>\n                            <div class=\"js-accordion-content fag-accordion__content\">\n                                <p>SLSA is not a regulation by itself, but it is useful for strengthening software supply chain practices that support frameworks and expectations such as SSDF, EO 14028-driven federal guidance, the EU CRA, NIS2, and sector-specific requirements like FDA cyber-device obligations.<\/p>\n                            <\/div>\n                        <\/div>\n                                                <div class=\"js-accordion__item fag-accordion__item \">\n                            <h3 class=\"js-accordion__btn fag-accordion__btn\">\n                                <svg width=\"34px\" height=\"23px\" viewbox=\"0 0 34 23\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\">\n                                    <g id=\"Page-1\" stroke=\"none\" stroke-width=\"1\" fill=\"none\" fill-rule=\"evenodd\">\n                                        <g id=\"Shape\" transform=\"translate(0.939453, 1.530000)\" stroke-width=\"3\">\n                                            <path d=\"M19.810947,20.4179 L31.029947,9.14 M30.029947,10.1989 L0,10.1989 M31.029947,11.26 L19.810947,0\"><\/path>\n                                        <\/g>\n                                    <\/g>\n                                <\/svg>\n                                Is SLSA only for advanced organizations?                            <\/h3>\n                            <div class=\"js-accordion-content fag-accordion__content\">\n                                <p>No. SLSA is designed to be incrementally adoptable, so organizations can improve over time rather than trying to implement every control at once.<\/p>\n                            <\/div>\n                        <\/div>\n                                        <\/div>\n            <\/div>\n        <\/div>\n    <\/div>\n<\/section>\n\n\n<script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@type\":\"FAQPage\",\"url\":\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is SLSA?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"SLSA is a software supply chain security framework that helps organizations improve build integrity, provenance, and trust in software artifacts. It stands for Supply-chain Levels for Software Artifacts.\"}},{\"@type\":\"Question\",\"name\":\"Who maintains SLSA?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"SLSA is maintained as a project of the Open Source Security Foundation, or OpenSSF, and developed through industry consensus.\"}},{\"@type\":\"Question\",\"name\":\"What does SLSA help prevent?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"SLSA helps organizations reduce the risk of tampering, compromised build processes, and other software supply chain attacks by strengthening trust in how software is built and delivered.\"}},{\"@type\":\"Question\",\"name\":\"What is provenance in SLSA?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"In SLSA, provenance is the metadata that describes where an artifact came from and how it was built. It is a key part of verifying integrity and trust.\"}},{\"@type\":\"Question\",\"name\":\"Is SLSA useful for compliance?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"SLSA is not a regulation by itself, but it is useful for strengthening software supply chain practices that support frameworks and expectations such as SSDF, EO 14028-driven federal guidance, the EU CRA, NIS2, and sector-specific requirements like FDA cyber-device obligations.\"}},{\"@type\":\"Question\",\"name\":\"Is SLSA only for advanced organizations?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"No. SLSA is designed to be incrementally adoptable, so organizations can improve over time rather than trying to implement every control at once.\"}}]}<\/script>","protected":false},"excerpt":{"rendered":"<p>Updated: 19\/04\/2026 What Is SLSA? SLSA, pronounced \u201csalsa,\u201d stands for Supply-chain Levels for Software Artifacts. It is a set of incrementally adoptable guidelines for software supply chain security that helps organizations strengthen the integrity of software artifacts and reduce the risk of tampering during software development and delivery. SLSA is maintained as a project of [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":106865,"template":"","glossary-tags":[],"class_list":["post-97693","glossary","type-glossary","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>SLSA Explained - Framework, Levels and Implementation Best Practices - Checkmarx<\/title>\n<meta name=\"description\" content=\"What is the SLSA Framework? Explore how SLSA helps prevent software supply chain attacks. Perfect for AppSec teams and developers aiming to secure SDLC.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SLSA Explained - Framework, Levels and Implementation Best Practices - Checkmarx\" \/>\n<meta property=\"og:description\" content=\"What is the SLSA Framework? Explore how SLSA helps prevent software supply chain attacks. Perfect for AppSec teams and developers aiming to secure SDLC.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:modified_time\" content=\"2026-04-23T14:58:35+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/03\/software-supply-chain-management.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/\",\"url\":\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/\",\"name\":\"SLSA Explained - Framework, Levels and Implementation Best Practices - Checkmarx\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/03\/software-supply-chain-management.webp\",\"datePublished\":\"2024-09-05T12:37:02+00:00\",\"dateModified\":\"2026-04-23T14:58:35+00:00\",\"description\":\"What is the SLSA Framework? Explore how SLSA helps prevent software supply chain attacks. Perfect for AppSec teams and developers aiming to secure SDLC.\",\"breadcrumb\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#primaryimage\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/03\/software-supply-chain-management.webp\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/03\/software-supply-chain-management.webp\",\"width\":1200,\"height\":600,\"caption\":\"software supply chain security cover\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Glossary\",\"item\":\"https:\/\/checkmarx.com\/glossary\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SLSA Explained &#8211; Framework, Levels and Implementation Best Practices\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"SLSA Explained - Framework, Levels and Implementation Best Practices - Checkmarx","description":"What is the SLSA Framework? Explore how SLSA helps prevent software supply chain attacks. Perfect for AppSec teams and developers aiming to secure SDLC.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/","og_locale":"en_US","og_type":"article","og_title":"SLSA Explained - Framework, Levels and Implementation Best Practices - Checkmarx","og_description":"What is the SLSA Framework? Explore how SLSA helps prevent software supply chain attacks. Perfect for AppSec teams and developers aiming to secure SDLC.","og_url":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_modified_time":"2026-04-23T14:58:35+00:00","og_image":[{"width":1200,"height":600,"url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/03\/software-supply-chain-management.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_site":"@checkmarx","twitter_misc":{"Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/","url":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/","name":"SLSA Explained - Framework, Levels and Implementation Best Practices - Checkmarx","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#primaryimage"},"thumbnailUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/03\/software-supply-chain-management.webp","datePublished":"2024-09-05T12:37:02+00:00","dateModified":"2026-04-23T14:58:35+00:00","description":"What is the SLSA Framework? Explore how SLSA helps prevent software supply chain attacks. Perfect for AppSec teams and developers aiming to secure SDLC.","breadcrumb":{"@id":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#primaryimage","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/03\/software-supply-chain-management.webp","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/03\/software-supply-chain-management.webp","width":1200,"height":600,"caption":"software supply chain security cover"},{"@type":"BreadcrumbList","@id":"https:\/\/checkmarx.com\/glossary\/what-is-the-slsa-framework\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Glossary","item":"https:\/\/checkmarx.com\/glossary\/"},{"@type":"ListItem","position":2,"name":"SLSA Explained &#8211; Framework, Levels and Implementation Best Practices"}]},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/97693","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/11"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/97693\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media\/106865"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=97693"}],"wp:term":[{"taxonomy":"glossary-tags","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary-tags?post=97693"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}