SLSA Explained: An Interview with Randy Abernethy

RX-M Managing Partner Randy Abernethy joins Ebenezer Don, the Founder of NewDev.io, on the Codegiant YouTube channel to discuss the importance of software supply chain security. Their conversation includes the need for secure artifact creation in software supply chains, the Supply-chain Levels for Software Artifacts (SLSA) framework, and how the Factory for Repeatable Secure Creation of Artifacts (FRSCA) reference implementation can help organizations get started securing their own build infrastructure.

Randy joins from the RX-M booth at KubeCon + CloudNativeCon North America in Chicago where software supply chain security was one of the most talked about topics of the show due to ever-increasing threats to software build systems, processes, and artifacts. The SLSA framework, and its reference implementation FRSCA, focus on enhancing the security of build platforms and increasing the trustworthiness of artifacts by providing transparency through software provenance, risk mitigation via hardening, and artifact integrity with digital signatures, among other things.

Don’t miss RX-M’s blog series on SLSA/FRSCA! In part 1 we discuss more about what SLSA is and why it is important. Part 2 covers the FRSCA implementation and tools used to build a FRSCA-based cluster, including Kubernetes, Helm, Tekton, Sigstore, and others. Follow along as we build a FRSCA cluster from the ground up!

Secret Link