论文标题
软件供应链属性完整性(SCAI)
Software Supply Chain Attribute Integrity (SCAI)
论文作者
论文摘要
软件供应链属性完整性或SCAI(发音为“ Sky”),规范提出了用于捕获有关软件伪像及其供应链的功能属性和完整性信息的数据格式。 SCAI数据可以与可执行的二进制文件,静态或动态链接的库,软件包,容器图像,软件工具链和计算环境相关联。 因此,SCAI旨在通过软件开发工具或服务(例如,建筑商,CI/CD管道,软件分析工具)作为现有软件供应链证明框架的一部分实施,旨在捕获有关其生产软件文物的属性和行为的更多详细信息。也就是说,SCAI假设实施者将拥有适当的过程和工具来捕获其他类型的软件供应链元数据,可以扩展以增加对SCAI的支持。
The Software Supply Chain Attribute Integrity, or SCAI (pronounced "sky"), specification proposes a data format for capturing functional attribute and integrity information about software artifacts and their supply chain. SCAI data can be associated with executable binaries, statically- or dynamically-linked libraries, software packages, container images, software toolchains, and compute environments. As such, SCAI is intended to be implemented as part of an existing software supply chain attestation framework by software development tools or services (e.g., builders, CI/CD pipelines, software analysis tools) seeking to capture more granular information about the attributes and behavior of the software artifacts they produce. That is, SCAI assumes that implementers will have appropriate processes and tooling in place for capturing other types of software supply chain metadata, which can be extended to add support for SCAI.