Skip to content

Commit

Permalink
Update index.md: update license attribution for figure
Browse files Browse the repository at this point in the history
per @svrnm editorial review 
#5718 (comment)
  • Loading branch information
horovits authored Dec 23, 2024
1 parent 021ab69 commit b460382
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion content/en/blog/2024/otel-cicd-sig/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,7 @@ But what does that actually mean? What value does it provide? Let’s consider r
### Artifacts for supply chain security, aligned with the SLSA specification

Check warning on line 66 in content/en/blog/2024/otel-cicd-sig/index.md

View workflow job for this annotation

GitHub Actions / SPELLING check

Unknown word (SLSA) Suggestions: (sisa, sosa, salsa, sisá, Sosa)

The [artifact attribute namespace](https://opentelemetry.io/docs/specs/semconv/attributes-registry/artifact/) had multiple attributes for its first implementation. One key set of attributes within this namespace cover [attestations](https://slsa.dev/attestation-model) that closely align with the [SLSA](https://slsa.dev/spec/v1.0/about) model. This is really the first time a direct connection is being made between Observability and Software Supply Chain Security. Consider the following [supply chain threat model](https://slsa.dev/spec/v1.0/threats) defined by SLSA:

Check warning on line 68 in content/en/blog/2024/otel-cicd-sig/index.md

View workflow job for this annotation

GitHub Actions / SPELLING check

Unknown word (SLSA) Suggestions: (sisa, sosa, salsa, sisá, Sosa)

Check warning on line 68 in content/en/blog/2024/otel-cicd-sig/index.md

View workflow job for this annotation

GitHub Actions / SPELLING check

Unknown word (SLSA) Suggestions: (sisa, sosa, salsa, sisá, Sosa)
![SLSA supply chain threat model diagram](SLSA-supply-chain-model.png)
{{< figure class="figure" src="SLSA-supply-chain-model.png" attr="SLSA Community Specification License 1.0" attrlink="https://github.com/slsa-framework/slsa?tab=License-1-ov-file" >}}

Check warning on line 69 in content/en/blog/2024/otel-cicd-sig/index.md

View workflow job for this annotation

GitHub Actions / SPELLING check

Unknown word (SLSA) Suggestions: (sisa, sosa, salsa, sisá, Sosa)

Check warning on line 69 in content/en/blog/2024/otel-cicd-sig/index.md

View workflow job for this annotation

GitHub Actions / SPELLING check

Unknown word (SLSA) Suggestions: (sisa, sosa, salsa, sisá, Sosa)

These new attributes for artifacts and attestations help observe the sequence of events modeled in the above diagram in real time. Really, the conventions that exist today and those that will be added in the future enable interoperability between core software delivery capabilities like security and platform engineering via observability semantics.

Expand Down

0 comments on commit b460382

Please sign in to comment.