diff --git a/README.md b/README.md index 7165a96..b48f5b2 100644 --- a/README.md +++ b/README.md @@ -2,7 +2,6 @@ [![OpenSSF Developer Best Practices](https://www.bestpractices.dev/projects/14648/badge)](https://www.bestpractices.dev/en/projects/14648/passing) [![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/nix-forge/.github/badge)](https://scorecard.dev/viewer/?uri=github.com/nix-forge/.github) -[![SLSA status](https://img.shields.io/badge/SLSA-status-blue)](https://github.com/nix-forge/.github/blob/main/docs/slsa.md) Organization workflow templates call the pinned release in [nix-forge/ci](https://github.com/nix-forge/ci). Choose a template in the Actions tab and select the systems your repository supports. Template edits do not update existing copies; Dependabot updates the shared workflow references. The complete repository map and shared security contract are in [PROJECTS.md](PROJECTS.md). diff --git a/docs/slsa.md b/docs/slsa.md index 4223709..61e5bba 100644 --- a/docs/slsa.md +++ b/docs/slsa.md @@ -1,8 +1,9 @@ # SLSA scope and adoption plan -Reviewed 21 September 2026 against the [approved SLSA 1.2 specification](https://slsa.dev/spec/v1.2/). The badge in each repository links here. It -means the repository has an assessed scope and a published plan; it does **not** assert -that every artifact or source revision has reached Level 3. +Reviewed 21 September 2026 against the +[approved SLSA 1.2 specification](https://slsa.dev/spec/v1.2/). This page records +each repository's assessed scope and next steps. No repository-wide SLSA level +is claimed. SLSA has separate [Build](https://slsa.dev/spec/v1.2/build-track-basics) and [Source](https://slsa.dev/spec/v1.2/source-requirements) tracks. Build levels apply to @@ -76,9 +77,10 @@ gh attestation verify nix-forge-ci-v2.8.0.tar.gz \ L3. Preserve Source L4 as a separate two-person review target. 5. **Maintain the claims.** For each claimed release, keep a verification command and record tied to the tag and builder commit. Reassess when the builder, release workflow, - runner, artifact set, branch rules, or distribution channel changes. Promote a badge - from "status" to a track and level only when its linked page identifies verified - subjects and the evidence for the current release. + runner, artifact set, branch rules, or distribution channel changes. Use a level badge + only if it names the Build or Source track and specification version and links to + verified subjects and evidence for the current release. A workflow status badge + reports whether CI passed; it does not verify a SLSA level. This plan describes provenance and release integrity. It does not replace vulnerability management, dependency review, reproducibility checks, or the security audit required for