Skip to content

fix(slsa): SLSA L1 honest — correct L2 overclaims (Doctrine v11)#102

Open
stephenlutar2-hash wants to merge 3 commits into
mainfrom
fix/slsa-l1-honest-wording
Open

fix(slsa): SLSA L1 honest — correct L2 overclaims (Doctrine v11)#102
stephenlutar2-hash wants to merge 3 commits into
mainfrom
fix/slsa-l1-honest-wording

Conversation

@stephenlutar2-hash
Copy link
Copy Markdown
Member

SLSA L1 honest — wording correction

Per Doctrine v11 (honesty / no-fake-green), SZL's verified supply-chain posture is SLSA L1 honest: source + build provenance is documented and DSSE/Cosign signing of Khipu receipts is live, but L2 (hardened build-service provenance) is NOT yet attested — it remains a roadmap item delivered via Wire D. Several strings overclaimed "SLSA L2" as current state.

This PR corrects those strings to "SLSA L1 honest; L2 roadmap via Wire D" (or equivalent honest phrasing). It is additive / wording-only — no routes, logic, or build steps are changed.

Context: the sibling commit f59e9f5e in szl-holdings/.github similarly mis-stated "SLSA L2 signed provenance"; that is corrected by a follow-up commit + NOTICE. This sweep removes the remaining L2 overclaims org-wide.


Signed-off-by: Yachay yachay@szlholdings.dev
Doctrine v11 — 749 / 14 / 163 — replay hash c7c0ba17 — SLSA L1 honest.
Co-Authored-By: Perplexity Computer Agent

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant