      Merge pull request #56 from MarkLodato/provisional · 21e12e71
      Remove "proposed" wording.
      Remove "proposed" wording. · 529afa03
      Minor changes to remove the notion that this is a "proposal" and instead
      just describe SLSA as it is.
      Also explain that levels 2-3 are likely to change in the future, rather
      than using some sort of symbol (*) or term (provisional), since
      technically all requirements are subject to change. It's just that 2-3
      are more likely to change.
      Merge pull request #55 from MarkLodato/clarification · acc814a1
      Clarify SLSA requirements.
      Clarify SLSA requirements. · d0c79147
      Changes to requirements:
      - Remove "Source Integrity", add immutable references to "Hermetic".
      - Drop "Common" from SLSA 2 because it is likely expensive.
      - Split out "Ephemeral Environment" from "Isolation" (from #52).
      - Explain that GH-generated merge commits meet Verified History (from #52).
      - Clarify that all artifact references are immutable (from #52).
      - Rename "Dependencies" to "Dependencies Complete" to avoid confusion.
      - Define "SLSA level", "provenance", and "top-level source."
      - Other minor cleanups.
  11. 08 Jun, 2021 4 commits
      Merge pull request #54 from MarkLodato/diagrams · 17b77918
      Update Vision section with latest changes.
      Update Vision section with latest changes. · 6ee42edd
      - Make the vision diagrams consistent with the terminology section:
        - Output is on the right, input is on the left.
        - Use colors consistently.
        - Rename "resource" to "artifact locator".
        - Simplify the diagram to reduce confusion (fixes #31).
      - Update the level explanations based on recent changes:
        - SLSA 1 is unsigned.
        - Add SLSA 1.5 (merged with the SLSA 2 section).
        - Minor wording updates.
      - Remove Deployment Policies section. We will eventually need to explain
        policies, but for now let's omit it until we agree on what that should
        look like.
      Merge pull request #53 from MarkLodato/terminology · 6f552a33
      Remove Resource and Deploy to simplify the model.
      Remove Resource and Deploy to simplify the model. · 03699118
      Previously, we differentiated between Resources and Artifacts, and SLSA
      was a property of a Resource's security policy. However, many readers
      found this concept very confusing.
      Now, SLSA is purely a property of the artifact. If provenance exists
      showing that it met the requirements, the artifact meets the level. No
      policy or notion of "resource" is required. This simplifies the model at
      some cost of security, which we have collectively decided is worth the
      NOTE: The Vision section will be updated in a future change.