Farm to Fork, Repo to Runtime: Preventing Digital Contamination with SLSA
Gøran Breivik
Om foredraget
I think of software a bit like food — it’s produced, processed, and
served to users through long and often messy supply chains.
And just as food safety relies on hygiene rules, labeling, and
traceability, we now need the same for software - to avoid our orgs
getting sick to their stomach. AI can probably help here as well.
More and more people vibe coding is not helping though.
In this talk, I’ll loosely use examples from food safety to explain SLSA
(Supply-chain Levels for Software Artifacts) — what it is, why it
matters, and how it can help us avoid the worst stomach flu.
We’ll move from farm to fork — or rather, from repo to runtime —
looking at provenance, attestations, and simple hygiene measures any
team can start with. We'll "discuss" if local produce may be
preferable to imported and so on.
It’s not a technical deep dive, but a structured story: how to
understand and apply SLSA in a practical way that actually fits real
organizations.