I ran a link checker and it reports a total of 16 broken links (out of 1080!!!), all of which are external/outbound, and 6 of which are "example.com" type of links and can be ignored.
The other links are broken because the destination which isn't under our control has changed.
There is one link in our spec which was reported in issue #1598 and which I'm following up on with the in-toto project as issue #547.
The other broken links are in old blog posts. I'm not sure that we should keep editing old blog posts though so I think we should agree on a general policy on how to handle these.
404 Not found
https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/
Linked from: https://slsa.dev/blog and 6 more
404 Not found
https://github.com/in-toto/attestation/blob/main/spec/predicates/spdx.md
Linked from: https://slsa.dev/spec/v1.2/source-requirements and 10+ more
404 Not found
https://github.com/carabiner-dev/demo-slsa-e2e/policies/fritoto-gate-publish.hjson
Linked from: https://slsa.dev/blog/2025/10/slsa-e2e-with-ampel
404 Not found
https://carabiner.dev/ampel@v1
Linked from: https://slsa.dev/blog/2025/10/slsa-e2e-with-ampel
404 Not found
https://github.com/carabiner-dev/demo-slsa-e2e/blob/main/policies/check-artifacts.json
Linked from: https://slsa.dev/blog/2025/10/slsa-e2e-with-ampel
404 Not found
https://github.com/slsa-framework/slsa-source-poc/blob/main/REQUIREMENTS_MAPPING.md
Linked from: https://slsa.dev/blog/2025/04/slsa-source-sprint
404 Not found
https://github.com/slsa-framework/slsa-source-poc/blob/main/DESIGN.md
Linked from: https://slsa.dev/blog/2025/04/slsa-source-sprint
404 Not found
https://www.whitehouse.gov/wp-content/uploads/2022/09/M-22-18.pdf
Linked from: https://slsa.dev/blog/2022/09/eo-in-plain-english
404 Not found
https://github.com/ossf/scorecard/blob/main/.github/workflows/slsa-goreleaser.yml
Linked from: https://slsa.dev/blog/2022/06/slsa-github-workflows
404 Not found
https://github.com/ossf/scorecard/blob/main/.slsa-goreleaser.yml
Linked from: https://slsa.dev/blog/2022/06/slsa-github-workflows
I ran a link checker and it reports a total of 16 broken links (out of 1080!!!), all of which are external/outbound, and 6 of which are "example.com" type of links and can be ignored.
The other links are broken because the destination which isn't under our control has changed.
There is one link in our spec which was reported in issue #1598 and which I'm following up on with the in-toto project as issue #547.
The other broken links are in old blog posts. I'm not sure that we should keep editing old blog posts though so I think we should agree on a general policy on how to handle these.