
- Preventive guardrails (policies, least privilege).
- Continuous visibility and detection (scanning, observability).
- Conformance and enforcement (attestations, admission policies).
SLSA (Supply-chain Levels for Software Artifacts) is a vendor-neutral maturity and attestation model for software supply chain security. It focuses on provenance, build integrity, and progressive cryptographic guarantees that apply across CI/CD platforms. Learn more at the SLSA project: https://slsa.dev.


- Start simple: implement Level 1 by generating build metadata and provenance that link artifacts to source (initially not cryptographically signed).
- Progressive enhancement: lock down build environments and provide isolation for runners (move toward Level 2).
- Tool integration: adopt signing/attestation tooling such as Sigstore/Cosign, Tekton Chains, and provenance stores.
- Policy enforcement: validate attestations at runtime and enforce SLSA-related policies through admission controllers or deployment gates.

- Container and artifact scanning
- Vulnerability scanning: detect known CVEs in images and packages.
- Configuration analysis: spot insecure container or OS settings.
- Malware detection: flag suspicious binaries or behaviors.
- License compliance: identify problematic open-source licenses.

- Supply chain transparency with SBOMs
- Generate a Software Bill of Materials (SBOM) to list components for traceability and license checks.
- Syft (Anchore / CNCF) produces SBOMs in SPDX and CycloneDX formats.

- Cryptographic signing and attestations
- Sigstore provides signing and transparency without owning a full PKI.
- Cosign (part of Sigstore tooling) signs container images and can verify signatures before deployment.
- Tekton Chains automates provenance attestation for Tekton Pipelines and integrates with Sigstore.


- Pre-commit: prevent secrets and obvious policy violations before code lands.
- CI pipeline: run security scans, dependency checks, SBOM generation, and policy validation.
- Registry/artifact scanning: re-scan images and artifacts after push.
- Admission control: enforce policies at deploy time (image signing, vulnerability thresholds, resource limits).

Never commit secrets to Git or bake them into container images. Use external secret stores (Vault, ExternalSecrets, or cloud provider secret managers) and inject secrets at runtime. Rotate secrets automatically and maintain an audit trail.
- Embedding API keys in code or Dockerfiles.
- Using environment variables in Dockerfiles that bake secrets into images.
- Storing plaintext DB passwords in manifests.

- Pre-commit scanners and GitHub secret scanning.
- TruffleHog, GitLeaks, and KICS to detect secrets in commits and repos.
- Treat IaC as code: run static checks, policy validations, and compliance scans before deployment.
- Tools: Checkov, tfsec, KICS, and Terrascan detect misconfigurations and policy violations.


- SAST: static analysis for code issues and insecure patterns.
- DAST/RST: dynamic or runtime testing of running services (e.g., OWASP ZAP, Nuclei).
- Integrate SAST and DAST into CI and staging environments to catch issues prior to production.

- Enforce namespace boundaries and Role-Based Access Control (RBAC).
- Apply resource quotas to avoid noisy-neighbor or resource exhaustion issues.
- Use NetworkPolicies for deny-by-default, zero-trust networking between tenants.
- Enforce Pod Security Standards to prevent insecure runtime contexts.

- Use ephemeral, isolated runners for builds (dedicated namespaces and networks).
- Enforce least privilege for runner identities and tokens.
- Scan artifacts immediately after build and scan running containers post-deployment.
- Level 2 SLSA depends on attesting to and protecting the build environment.


- Modern applications include many third-party libraries; dependency confusion and malicious packages are real threats.
- Maintain inventories, track versions, and perform risk-based updates.
- Use caching, parallel scanning, and deduplication to reduce scanning overhead while preserving developer velocity.

- Use progressive scanning based on risk (full scans for changed or new components; cached results for unchanged signed artifacts).
- Consolidate toolchains where it makes sense to reduce tool sprawl.
- Auto-scale scanning infrastructure so security checks do not become a pipeline bottleneck.

- Scan deduplication: skip rescans for verified, signed artifacts.
- Tool consolidation: select a small set of integrated scanners and attestation tools.
- Resource scaling: ensure scanners and pipelines scale with demand to maintain throughput.

- Service meshes (Istio, Linkerd) provide automatic mTLS, identity-based policies, traffic monitoring, and enforcement controls — useful primitives for runtime segmentation and observability.

- Maintain audit logs, security metrics, and automated alerting.
- Integrate detection and response into platform tooling so incidents can be triaged and traced end-to-end.

- Keep Policy-as-Code, audit trails, and retained evidence to satisfy SOC2, GDPR, and other regulations.
- Use encryption in transit and at rest, secure logs, and preserve signed artifacts and SBOMs as compliance evidence.


- Adopt SLSA progressively: start with provenance (Level 1), harden build environments (Level 2), protect source and signing (Level 3), and aim for hermetic builds (Level 4) where feasible.
- Use multi-layer scanning: vulnerabilities, secrets, IaC, SAST/DAST, and runtime checks.
- Generate SBOMs and integrate cryptographic signing (Sigstore/Cosign, Tekton Chains) so artifacts can be verified at deploy time.
- Secure runners, isolate build networks, apply least privilege, and inject secrets at runtime from external secret stores.
- Balance security with developer velocity using caching, deduplication, and scalable scanning infrastructure.

- SLSA: https://slsa.dev
- Trivy: https://github.com/aquasecurity/trivy
- Syft (SBOM): https://github.com/anchore/syft
- Sigstore / Cosign: https://sigstore.dev
- Tekton Chains: https://tekton.dev/docs/chains
- Kyverno: https://kyverno.io
- Kubernetes concepts: https://kubernetes.io/docs/concepts/overview/what-is-kubernetes/