# Chainguard and CNCF conduct SLSA assessments for Argo and Prometheus projects

DevFeed: [Chainguard and CNCF conduct SLSA assessments for Argo and Prometheus projects](<https://devfeed.tech/articles/chainguard-and-cncf-conduct-slsa-assessments-for-argo-and-prometheus-projects-12923.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-and-cncf-conduct-slsa-assessments-for-argo-and-prometheus-projects>)

Published: 2023-04-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Prometheus](<https://devfeed.tech/topics/prometheus.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [argo](<https://devfeed.tech/tags/argo.md>), [argo-cd](<https://devfeed.tech/tags/argo-cd.md>), [audits](<https://devfeed.tech/tags/audits.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [cncf](<https://devfeed.tech/tags/cncf.md>), [github](<https://devfeed.tech/tags/github.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [prometheus](<https://devfeed.tech/tags/prometheus.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [slsa-levels](<https://devfeed.tech/tags/slsa-levels.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>)

## AI overview

Chainguard and CNCF assessed the software supply chain security of the Argo CD and Prometheus projects using the SLSA framework. Argo CD achieved SLSA Level 3 for source, build, and provenance, while Prometheus achieved Level 3 for source and build; the assessment recommended adding provenance generation to Prometheus build infrastructure.

## Source excerpt

Chainguard and the CNCF partnered to conduct security assessments of Argo and Prometheus to ensure open source software projects apply security best practices.