Last updated: April 29, 2026
Why this module. 2020 SolarWinds taught the industry that “we trust our build pipeline” is no longer enough. SLSA (Supply-chain Levels for Software Artifacts) is Google’s framework for hardening builds against supply-chain attacks. By 2026, several Indian regulated entities have begun requiring SLSA L2+ attestations from vendors.
The four SLSA levels
| Level | What’s required | Roughly |
|---|---|---|
| L0 | No requirements | Default — most software |
| L1 | Build process automated; provenance generated | You have CI; you can produce a build log |
| L2 | Tamper-resistant build; signed provenance from a trusted source | GitHub Actions with attestation, GitLab CI signed |
| L3 | Hardened build platform; isolated, ephemeral builds; non-falsifiable provenance | Production-grade build platform; Sigstore |
L4 was originally defined but has been restructured in SLSA 1.0; in practice “L3 + reproducibility + two-person review” is roughly L4-equivalent.
Custom team training + practitioner advisory
Beyond the free academy — we run private workshops, vCISO advisory, and red-team exercises tailored to your stack. For Indian SMBs scaling past their first hire.