Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

blog: Add blog post announcing v1.1 RC2 #1317

Merged
merged 11 commits into from
Apr 4, 2025
43 changes: 43 additions & 0 deletions docs/_posts/2025-04-04-slsa-v1.1-rc2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
---
title: Announcing SLSA v1.1 Release Candidate 2
author: "SLSA Community"
is_guest_post: false
---

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we should add a short list of bullet points that briefly describes what we want out of this blog post. E.g.

Summary

  • SLSA v1.1 RC2 introduces backwards-compatible clarifications to the SLSA threat model, attestation model and verification procedure
  • We're seeking comments on these spec changes by April 18, 2025

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sounds good to me. Thanks!

Since the publication of [SLSA 1.0](/spec/v1.0/) back in April 2023, the
SLSA specification community has been busy developing several new tracks
covering areas such as source and build environment. While we are excited
about these additions, we wanted to publish other improvements that were
made to the specification without waiting for those additions. To that end
[SLSA Version 1.1 Release Candidate 1 (RC1)](/spec/v1.1-rc1/) was published
in August 2024.

During the review period we found out several loose ends with the updated
threat model section, which forced us to go through another round of
edits. While this took longer than we had anticipated (mostly due to the
fact that the main contributors were focusing on developing the new
tracks), we are pleased to announce that [Version 1.1 RC2](/spec/v1.1-rc2/)
is now available for review.

This new version brings several changes aimed at enhancing the clarity and
usability of the specification. In particular, this update refines the threat
model and possible mitigations, clarifies the role of attestation format
schemas and procedure for verifying Verification Summary Attestations (VSA),
and adds verifier metadata to the VSA. Please, refer to the [What's
new](/spec/v1.1-rc2/whats-new) section for further details.

It is worth noting that SLSA 1.1 is backwards compatible with SLSA 1.0.

The SLSA specification follows the [Community Specification] lifecycle
going through several [stages of maturation](/spec-stages). The publication
of a candidate for [Approved Specification] starts a 2 week review period
during which the community at large is invited to review the draft and
raise any issues. If you do find any issue, please, open an issue on
[GitHub]. If no major issues are found during this review period the V1.1
RC2 draft will then be published as Version 1.1, the new [Approved
Specification], effectively replacing Version 1.0.

[Community Specification]: https://github.com/CommunitySpecification/Community_Specification/blob/main/
[GitHub]: https://github.com/slsa-framework/slsa/issues
[backlog]: https://github.com/orgs/slsa-framework/projects/1/views/1
[Approved Specification]: /spec-stages#approved