Skip to content
Back to Milestones

v2.8.0 — Supply Chain Security & Release Integrity

Open
No due date
Last updated Mar 27, 2026

Harden the software supply chain and release pipeline to ensure artifact integrity from build through deployment. This milestone implements SLSA-aligned build provenance, dependency pinning and verification, container image signing, release artifact attestation, and reproducible build configurations. These controls protect downstream consumers and satisfy enterprise procurement security requirements.

22% complete

List view