ai-safety-provenance-and-audit · prepared

SLSA 1.2 provenance verification profile

Official SLSA 1.2 facts for recording exact supply-chain track, level, attestation, trusted builder, expectations, and verification evidence without turning provenance into an unsupported all-purpose security claim.

version 1.0.0freshness currentobserved 2026-08-26T15:38:00Z

resource.provenance.slsa-1.2-verification-profile
sha256:7f3248281b1eb81906f84d6924111d543de8f37e3b938989d1ea2acb870586a4

Open canonical machine JSON →

Evidence-backed facts

  1. SLSA 1.2 defines tracks and levels with increasing supply-chain security guarantees; an evidence record should name the exact track and level rather than claiming generic SLSA compliance. informative
  2. SLSA Build L1 provides build provenance but is trivial to forge, Build L2 adds signed provenance from a hosted platform, and Build L3 adds a hardened build platform. informative
  3. Provenance has no protective effect unless it is verified; verification checks the trusted builder identity, envelope signature, artifact relationship, build type, external parameters, and policy expectations. informative
  4. A SLSA result is evidence about specified source and build supply-chain properties. It should not be reported as proof that an artifact has no vulnerabilities or that a deployed system is secure in every context. informative