<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>/blog/2022/04/blog-launch</loc>
<lastmod>2022-04-08T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2022/04/slsa-is-no-free-lunch</loc>
<lastmod>2022-04-11T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2022/05/slsa-sbom</loc>
<lastmod>2022-05-02T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2022/06/slsa-ssdf</loc>
<lastmod>2022-06-15T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2022/06/slsa-github-workflows</loc>
<lastmod>2022-06-20T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2022/07/slsa-foundational-framework</loc>
<lastmod>2022-07-25T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2022/08/slsa-github-workflows-generic-ga</loc>
<lastmod>2022-08-29T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2022/09/eo-in-plain-english</loc>
<lastmod>2022-09-26T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2022/12/gcb-slsa-verification</loc>
<lastmod>2022-12-05T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/02/slsa-github-workflows-container-ga</loc>
<lastmod>2023-02-01T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/02/slsa-v1-rc</loc>
<lastmod>2023-02-24T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/04/the-breadth-and-depth-of-slsa</loc>
<lastmod>2023-04-03T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/04/slsa-v1-rc2</loc>
<lastmod>2023-04-04T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/04/slsa-v1-final</loc>
<lastmod>2023-04-19T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/05/in-toto-and-slsa</loc>
<lastmod>2023-05-02T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/05/bringing-improved-supply-chain-security-to-the-nodejs-ecosystem</loc>
<lastmod>2023-05-11T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/06/slsa-github-workflows-container-based</loc>
<lastmod>2023-06-13T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2023/08/bring-your-own-builder-github</loc>
<lastmod>2023-08-28T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2024/04/tekton-chains-ibm-devsecops</loc>
<lastmod>2024-04-16T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2024/08/dep-confusion-and-typosquatting</loc>
<lastmod>2024-08-13T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/04/slsa-v1.1-rc2</loc>
<lastmod>2025-04-04T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/04/slsa-v1.1</loc>
<lastmod>2025-04-21T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/04/slsa-source-sprint</loc>
<lastmod>2025-04-29T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/06/slsa-v1.2-rc1</loc>
<lastmod>2025-06-20T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/07/slsa-e2e</loc>
<lastmod>2025-07-22T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/10/slsa-e2e-with-ampel</loc>
<lastmod>2025-10-21T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/11/slsa-v1.2-rc2</loc>
<lastmod>2025-11-10T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/11/announce-slsa-v1.2</loc>
<lastmod>2025-11-24T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/blog/2025/12/supply-chain-robots-slsa</loc>
<lastmod>2025-12-18T00:00:00+00:00</lastmod>
</url>
<url>
<loc>/spec/draft/about</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/about</loc>
</url>
<url>
<loc>/spec/v1.0/about</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/about</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/about</loc>
</url>
<url>
<loc>/spec/v1.1/about</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/about</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/about</loc>
</url>
<url>
<loc>/spec/v1.2/about</loc>
</url>
<url>
<loc>/spec/draft/assessing-build-platforms</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/assessing-build-platforms</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/assessing-build-platforms</loc>
</url>
<url>
<loc>/spec/v1.2/assessing-build-platforms</loc>
</url>
<url>
<loc>/spec/draft/assessing-source-systems</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/assessing-source-systems</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/assessing-source-systems</loc>
</url>
<url>
<loc>/spec/v1.2/assessing-source-systems</loc>
</url>
<url>
<loc>/spec/draft/attestation-model</loc>
</url>
<url>
<loc>/spec/v0.1/attestation-model</loc>
</url>
<url>
<loc>/spec/v0.2/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.0/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.1/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/attestation-model</loc>
</url>
<url>
<loc>/spec/v1.2/attestation-model</loc>
</url>
<url>
<loc>/attestation-model</loc>
</url>
<url>
<loc>/blog</loc>
</url>
<url>
<loc>/spec/draft/build-env-track-basics</loc>
</url>
<url>
<loc>/spec/draft/build-provenance</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/build-provenance</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/build-provenance</loc>
</url>
<url>
<loc>/spec/v1.2/build-provenance</loc>
</url>
<url>
<loc>/spec/draft/build-requirements</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/build-requirements</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/build-requirements</loc>
</url>
<url>
<loc>/spec/v1.2/build-requirements</loc>
</url>
<url>
<loc>/spec/draft/build-track-basics</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/build-track-basics</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/build-track-basics</loc>
</url>
<url>
<loc>/spec/v1.2/build-track-basics</loc>
</url>
<url>
<loc>/community</loc>
</url>
<url>
<loc>/current-activities</loc>
</url>
<url>
<loc>/spec/draft/dependency-track</loc>
</url>
<url>
<loc>/spec/draft/distributing-provenance</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/distributing-provenance</loc>
</url>
<url>
<loc>/spec/v1.0/distributing-provenance</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/distributing-provenance</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/distributing-provenance</loc>
</url>
<url>
<loc>/spec/v1.1/distributing-provenance</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/distributing-provenance</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/distributing-provenance</loc>
</url>
<url>
<loc>/spec/v1.2/distributing-provenance</loc>
</url>
<url>
<loc>/spec/draft/faq</loc>
</url>
<url>
<loc>/spec/v0.1/faq</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/faq</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/faq</loc>
</url>
<url>
<loc>/spec/v1.0/faq</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/faq</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/faq</loc>
</url>
<url>
<loc>/spec/v1.1/faq</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/faq</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/faq</loc>
</url>
<url>
<loc>/spec/v1.2/faq</loc>
</url>
<url>
<loc>/spec/draft/future-directions</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/future-directions</loc>
</url>
<url>
<loc>/spec/v1.0/future-directions</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/future-directions</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/future-directions</loc>
</url>
<url>
<loc>/spec/v1.1/future-directions</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/future-directions</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/future-directions</loc>
</url>
<url>
<loc>/spec/v1.2/future-directions</loc>
</url>
<url>
<loc>/how-to/get-started</loc>
</url>
<url>
<loc>/how-to/how-to-infra</loc>
</url>
<url>
<loc>/how-to/how-to-orgs</loc>
</url>
<url>
<loc>/how-to/</loc>
</url>
<url>
<loc>/notes/</loc>
</url>
<url>
<loc>/spec/draft/</loc>
</url>
<url>
<loc>/spec/v0.1/</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/</loc>
</url>
<url>
<loc>/spec/v1.0/</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/</loc>
</url>
<url>
<loc>/spec/v1.1/</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/</loc>
</url>
<url>
<loc>/spec/v1.2/</loc>
</url>
<url>
<loc>/</loc>
</url>
<url>
<loc>/spec/v0.1/levels</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/levels</loc>
</url>
<url>
<loc>/spec/v1.0/levels</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/levels</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/levels</loc>
</url>
<url>
<loc>/spec/v1.1/levels</loc>
</url>
<url>
<loc>/spec/draft/onepage</loc>
</url>
<url>
<loc>/spec/v0.1/onepage</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/onepage</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/onepage</loc>
</url>
<url>
<loc>/spec/v1.0/onepage</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/onepage</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/onepage</loc>
</url>
<url>
<loc>/spec/v1.1/onepage</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/onepage</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/onepage</loc>
</url>
<url>
<loc>/spec/v1.2/onepage</loc>
</url>
<url>
<loc>/spec/draft/principles</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/principles</loc>
</url>
<url>
<loc>/spec/v1.0/principles</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/principles</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/principles</loc>
</url>
<url>
<loc>/spec/v1.1/principles</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/principles</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/principles</loc>
</url>
<url>
<loc>/spec/v1.2/principles</loc>
</url>
<url>
<loc>/spec/draft/provenance</loc>
</url>
<url>
<loc>/spec/v0.1/provenance</loc>
</url>
<url>
<loc>/spec/v0.2/provenance</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/provenance</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/provenance</loc>
</url>
<url>
<loc>/spec/v1.0/provenance</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/provenance</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/provenance</loc>
</url>
<url>
<loc>/spec/v1.1/provenance</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/provenance</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/provenance</loc>
</url>
<url>
<loc>/spec/v1.2/provenance</loc>
</url>
<url>
<loc>/spec/draft/requirements</loc>
</url>
<url>
<loc>/spec/v0.1/requirements</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/requirements</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/requirements</loc>
</url>
<url>
<loc>/spec/v1.0/requirements</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/requirements</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/requirements</loc>
</url>
<url>
<loc>/spec/v1.1/requirements</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/requirements</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/requirements</loc>
</url>
<url>
<loc>/spec/v1.2/requirements</loc>
</url>
<url>
<loc>/spec/draft/source-example-controls</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/source-example-controls</loc>
</url>
<url>
<loc>/spec/v1.2/source-example-controls</loc>
</url>
<url>
<loc>/spec/draft/source-requirements</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/source-requirements</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/source-requirements</loc>
</url>
<url>
<loc>/spec/v1.2/source-requirements</loc>
</url>
<url>
<loc>/spec/draft/source-track-assessment</loc>
</url>
<url>
<loc>/spec/draft/source-track-basics</loc>
</url>
<url>
<loc>/spec/draft/source-track-controls</loc>
</url>
<url>
<loc>/spec/draft/source-track-provenance</loc>
</url>
<url>
<loc>/spec/draft/source-track-requirements</loc>
</url>
<url>
<loc>/spec/draft/source-track-verification</loc>
</url>
<url>
<loc>/spec-stages</loc>
</url>
<url>
<loc>/spec/draft/terminology</loc>
</url>
<url>
<loc>/spec/v0.1/terminology</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/terminology</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/terminology</loc>
</url>
<url>
<loc>/spec/v1.0/terminology</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/terminology</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/terminology</loc>
</url>
<url>
<loc>/spec/v1.1/terminology</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/terminology</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/terminology</loc>
</url>
<url>
<loc>/spec/v1.2/terminology</loc>
</url>
<url>
<loc>/spec/draft/threats-overview</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/threats-overview</loc>
</url>
<url>
<loc>/spec/v1.0/threats-overview</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/threats-overview</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/threats-overview</loc>
</url>
<url>
<loc>/spec/v1.1/threats-overview</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/threats-overview</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/threats-overview</loc>
</url>
<url>
<loc>/spec/v1.2/threats-overview</loc>
</url>
<url>
<loc>/spec/draft/threats</loc>
</url>
<url>
<loc>/spec/v0.1/threats</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/threats</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/threats</loc>
</url>
<url>
<loc>/spec/v1.0/threats</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/threats</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/threats</loc>
</url>
<url>
<loc>/spec/v1.1/threats</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/threats</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/threats</loc>
</url>
<url>
<loc>/spec/v1.2/threats</loc>
</url>
<url>
<loc>/spec/draft/tracks</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/tracks</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/tracks</loc>
</url>
<url>
<loc>/spec/v1.2/tracks</loc>
</url>
<url>
<loc>/spec/draft/use-cases</loc>
</url>
<url>
<loc>/spec/v0.1/use-cases</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/use-cases</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/use-cases</loc>
</url>
<url>
<loc>/spec/v1.0/use-cases</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/use-cases</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/use-cases</loc>
</url>
<url>
<loc>/spec/v1.1/use-cases</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/use-cases</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/use-cases</loc>
</url>
<url>
<loc>/spec/v1.2/use-cases</loc>
</url>
<url>
<loc>/spec/draft/verification_summary</loc>
</url>
<url>
<loc>/spec/v0.1/verification_summary</loc>
</url>
<url>
<loc>/spec/v0.2/verification_summary</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/verification_summary</loc>
</url>
<url>
<loc>/spec/v1.0/verification_summary</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/verification_summary</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/verification_summary</loc>
</url>
<url>
<loc>/spec/v1.1/verification_summary</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/verification_summary</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/verification_summary</loc>
</url>
<url>
<loc>/spec/v1.2/verification_summary</loc>
</url>
<url>
<loc>/spec/draft/verified-properties</loc>
</url>
<url>
<loc>/spec/draft/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.0/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.1/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.2/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/draft/verifying-source</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/verifying-source</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/verifying-source</loc>
</url>
<url>
<loc>/spec/v1.2/verifying-source</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/verifying-systems</loc>
</url>
<url>
<loc>/spec/v1.0/verifying-systems</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/verifying-systems</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/verifying-systems</loc>
</url>
<url>
<loc>/spec/v1.1/verifying-systems</loc>
</url>
<url>
<loc>/spec/draft/whats-new</loc>
</url>
<url>
<loc>/spec/v1.0-rc2/whats-new</loc>
</url>
<url>
<loc>/spec/v1.0/whats-new</loc>
</url>
<url>
<loc>/spec/v1.1-rc1/whats-new</loc>
</url>
<url>
<loc>/spec/v1.1-rc2/whats-new</loc>
</url>
<url>
<loc>/spec/v1.1/whats-new</loc>
</url>
<url>
<loc>/spec/v1.2-rc1/whats-new</loc>
</url>
<url>
<loc>/spec/v1.2-rc2/whats-new</loc>
</url>
<url>
<loc>/spec/v1.2/whats-new</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/future-directions</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/levels</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/principles</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/verifying-artifacts</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/verifying-systems</loc>
</url>
<url>
<loc>/spec/v1.0-rc1/whats-new</loc>
</url>
</urlset>
