sscsb

phase-0 · bootstrap

Supply chain
security,
stamped in.

44 verifiable controls across five phases — secret scanning, signing policy, SBOMs, provenance, SAST — bootstrapped into any repo in one command. An unperformed check is never a verdict.

brew install p4gs/p4gs/sscsb
Browse the directory →
VERIFICATION RECEIPT sscsb 0.3.0
$ sscsb verify
[PASS] secrets · trufflehog + gitleaks
[PASS] commit-signing · human-only on main
[PASS] branch-protection · PRs · sigs · checks
[PASS] slsa-provenance · build L3
[FAIL] harden-runner · 1 job unmonitored
[·····] signing-model · awaiting attestation
verify: 1 failed, 1 degraded
PHASE-1
Commit integrity
Secrets blocked at the hook. Humans sign; AI declares.
PHASE-2
Dependencies
SBOMs, dual scanners, a trust gate for every new package.
PHASE-3
Provenance
Keyless signatures and SLSA attestations, bound to digests.
PHASE-4
SAST & CI
OpenGrep, CodeQL, egress-monitored, pinned workflows.
PHASE-5
Posture
VEX, Security Insights, a compliance map that stays true.

The public directory

Every listed repository was scanned with sscsb itself and scored by a published, versioned methodology. Evidence the scanner created never counts. Checks that couldn't run are shown, not spun.

B

Grades are inspection seals: A+ is reserved for exactly 100%. Unverified controls sit outside every denominator.

Authenticated scans

External scans are honest about their limits. Run sscsb-action in your own CI to publish a record that sees what an outside scan cannot — through the same reviewed gate.