Skip to content

SLSA Framework in New CD Foundation Cybersecurity Guide #1507

Description

@k8scarcella

Dear maintainers of SLSA Framework,

Our group at the Continuous Delivery Foundation created a CI/CD Cybersecurity Guide and the OpenSSF projects are featured in it.

[Request] Please double check that we categorized your project properly (or didn’t forget any).
https://cd.foundation/cybersecurity/

If you like our work, please share it with others

Sample social post:
Do DevSecOps the right way. Follow this CI/CD Cybersecurity Guide from the CD Foundation.
https://cd.foundation/blog/2025/09/30/cybersecurity-guide/

Activity

  1. TomHennen commented on Nov 3, 2025

    @TomHennen
    Contributor

    TODO:

    1. Check if it's categorized properly (if at all).
    2. Ensure it's not too specific and point back to SLSA
    3. See if they should link to some else like the Security Baseline.
  2. arewm commented on Nov 3, 2025

    @arewm
    Member

    @k8scarcella, I don't see SLSA mentioned anywhere in the https://cicd-cybersecurity.netlify.app/cicd-security-guide/ off hand. Do you know if SLSA is mentioned anywhere that I didn't find?

    Most of the links seemed to be about specific tools. As SLSA is not a tool, do you think that there would be a good location to call out a framework as only the SSDF is mentioned across the stages, i.e. https://cicd-cybersecurity.netlify.app/cicd-security-guide/phase-1/ssdf/ ?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions