# New SLSA++ Survey reveals real-world developer approaches to software supply chain security

DevFeed: [New SLSA++ Survey reveals real-world developer approaches to software supply chain security](<https://devfeed.tech/articles/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security-13183.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/new-slsa-survey-reveals-real-world-developer-approaches-to-software-supply-chain-security>)

Published: 2023-03-15T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [openssf](<https://devfeed.tech/topics/openssf.md>)

Tags: [best-practices](<https://devfeed.tech/tags/best-practices.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [digital-signatures](<https://devfeed.tech/tags/digital-signatures.md>), [integrity](<https://devfeed.tech/tags/integrity.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [openssf](<https://devfeed.tech/tags/openssf.md>), [report](<https://devfeed.tech/tags/report.md>), [rust](<https://devfeed.tech/tags/rust.md>), [secure-software-development-frameworks](<https://devfeed.tech/tags/secure-software-development-frameworks.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-development](<https://devfeed.tech/tags/software-development.md>), [software-security-practices](<https://devfeed.tech/tags/software-security-practices.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>), [supply-chain-integrity](<https://devfeed.tech/tags/supply-chain-integrity.md>), [supply-chain-security](<https://devfeed.tech/tags/supply-chain-security.md>), [survey](<https://devfeed.tech/tags/survey.md>)

## AI overview

A joint survey by Chainguard, the Eclipse Foundation, the Rust Foundation, and OpenSSF examined how developers, open source maintainers, and security practitioners adopt software supply chain security practices. Among nearly 170 respondents, centralized build services showed relatively strong adoption, while consistently signing built artifacts was less common, with 25% reporting that their team always did so. Respondents generally considered the surveyed practices helpful.

## Source excerpt

Findings on software supply chain security practice adoption from our joint survey with OpenSSF, Rust, and Eclipse with questions derived from SLSA requirements.