phase-0 · bootstrap
Supply chain
security,
stamped in.
44 verifiable controls across five phases — secret scanning, signing policy, SBOMs, provenance, SAST — bootstrapped into any repo in one command. An unperformed check is never a verdict.
brew install p4gs/p4gs/sscsb
Browse the directory →
VERIFICATION RECEIPT
sscsb 0.3.0
$ sscsb verify
[PASS] secrets · trufflehog + gitleaks
[PASS] commit-signing · human-only on main
[PASS] branch-protection · PRs · sigs · checks
[PASS] slsa-provenance · build L3
[FAIL] harden-runner · 1 job unmonitored
[·····] signing-model · awaiting attestation
verify: 1 failed, 1 degraded
PHASE-1
Commit integrity
Secrets blocked at the hook. Humans sign; AI declares.
PHASE-2
Dependencies
SBOMs, dual scanners, a trust gate for every new package.
PHASE-3
Provenance
Keyless signatures and SLSA attestations, bound to digests.
PHASE-4
SAST & CI
OpenGrep, CodeQL, egress-monitored, pinned workflows.
PHASE-5
Posture
VEX, Security Insights, a compliance map that stays true.
The public directory
Every listed repository was scanned with sscsb itself and scored by a published, versioned methodology. Evidence the scanner created never counts. Checks that couldn't run are shown, not spun.
B
Grades are inspection seals: A+ is reserved for exactly 100%. Unverified controls sit outside every denominator.
Authenticated scans
External scans are honest about their limits. Run sscsb-action in your own CI to publish a record that sees what an outside scan cannot — through the same reviewed gate.