# This Shit is Hard: SLSA L3 and Beyond

DevFeed: [This Shit is Hard: SLSA L3 and Beyond](<https://devfeed.tech/articles/this-shit-is-hard-slsa-l3-and-beyond-13288.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/this-shit-is-hard-slsa-l3-and-beyond>)

Published: 2025-07-31T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [containers](<https://devfeed.tech/tags/containers.md>), [provenance](<https://devfeed.tech/tags/provenance.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [signing](<https://devfeed.tech/tags/signing.md>), [slsa](<https://devfeed.tech/tags/slsa.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [software-supply-chain-security](<https://devfeed.tech/tags/software-supply-chain-security.md>)

## AI overview

Chainguard explains how it uses SLSA to strengthen software supply chain security, support customer compliance, and build trust in hardened container images. The article focuses on SLSA Build Level 3, especially isolated build execution and tamper-resistant provenance attestations with signing secrets separated from build and test processes.

## Source excerpt

Chainguard goes through all the necessary steps to make things SLSA 3 compliant. Get the details on how we do it.