Android and iOS

SLSA and mobile build provenance

OWASP, secure development and the evidence behind controls.

Standards and evidence1 min readEditorial methods

SLSA supports discussion of build and supply-chain trust. Keep source provenance connected to the final protected mobile artifact.

Evaluation approach

Trace source revisions, dependencies, build environments and outputs. Include any external RASP processing service in the chain. Distinguish pre- and post-protection artifacts.

Application example

Hash the source build and protected output separately, then verify the package sent to the store. Avoid distributing signing authority across arbitrary workstations.

Limits and considerations

Provenance does not prove the absence of business-logic vulnerabilities. Its issuer and verification process are also part of the trust model.

Checks and decisions

  • Record build inputs
  • Include protection processing
  • Match published outputs

Use provenance in release decisions so unexpected producers or outputs trigger a meaningful response.

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.