Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 0 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,6 @@

[![OpenSSF Developer Best Practices](https://www.bestpractices.dev/projects/14648/badge)](https://www.bestpractices.dev/en/projects/14648/passing)
[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/nix-forge/.github/badge)](https://scorecard.dev/viewer/?uri=github.com/nix-forge/.github)
[![SLSA status](https://img.shields.io/badge/SLSA-status-blue)](https://github.com/nix-forge/.github/blob/main/docs/slsa.md)

Organization workflow templates call the pinned release in [nix-forge/ci](https://github.com/nix-forge/ci). Choose a template in the Actions tab and select the systems your repository supports. Template edits do not update existing copies; Dependabot updates the shared workflow references. The complete repository map and shared security contract are in [PROJECTS.md](PROJECTS.md).

Expand Down
14 changes: 8 additions & 6 deletions docs/slsa.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,9 @@
# SLSA scope and adoption plan

Reviewed 21 September 2026 against the [approved SLSA 1.2 specification](https://slsa.dev/spec/v1.2/). The badge in each repository links here. It
means the repository has an assessed scope and a published plan; it does **not** assert
that every artifact or source revision has reached Level 3.
Reviewed 21 September 2026 against the
[approved SLSA 1.2 specification](https://slsa.dev/spec/v1.2/). This page records
each repository's assessed scope and next steps. No repository-wide SLSA level
is claimed.

SLSA has separate [Build](https://slsa.dev/spec/v1.2/build-track-basics) and
[Source](https://slsa.dev/spec/v1.2/source-requirements) tracks. Build levels apply to
Expand Down Expand Up @@ -76,9 +77,10 @@ gh attestation verify nix-forge-ci-v2.8.0.tar.gz \
L3. Preserve Source L4 as a separate two-person review target.
5. **Maintain the claims.** For each claimed release, keep a verification command and
record tied to the tag and builder commit. Reassess when the builder, release workflow,
runner, artifact set, branch rules, or distribution channel changes. Promote a badge
from "status" to a track and level only when its linked page identifies verified
subjects and the evidence for the current release.
runner, artifact set, branch rules, or distribution channel changes. Use a level badge
only if it names the Build or Source track and specification version and links to
verified subjects and evidence for the current release. A workflow status badge
reports whether CI passed; it does not verify a SLSA level.

This plan describes provenance and release integrity. It does not replace vulnerability
management, dependency review, reproducibility checks, or the security audit required for
Expand Down