Ch 6 · Pipeline security
Maturity ladder
28 / 32

SLSA grades the pipeline's trust — not any one artifact.

From Google's own internal "Binary Authorization for Borg," generalized industry-wide.

L1
Documented

A record exists

L2
Hosted, tamper-evident

Can't be quietly altered

L3
Hardened platform

Can't be forged

Common exam trap: SLSA Level 3 does NOT mean zero vulnerabilities. It certifies the build platform's tamper-resistance — a Level 3 pipeline can still faithfully ship a vulnerable dependency. That's Artifact Analysis's separate job.