sscsb

COMMIT → RELEASE, ACCOUNTED FOR

Every link in the chain, verified in the open.

sscsb walks your supply chain phase by phase and shows its work — what passed, what failed, and what genuinely couldn't be checked.

verified needs attention unverified — outside the math

sscsb's own repository, scanned by sscsb — a snapshot from the public directory. Provenance is mid-adoption, and the chain says so.

Scan your repository brew install p4gs/p4gs/sscsb

Public directory

3 repositories scanned with sscsb itself and scored by a published, versioned methodology. Every record passes a maintainer's review before it appears.

Browse the directory →

Honest math

A check that could not run is unverified — a third state, shown hatched and kept outside every denominator. An unperformed check is never a verdict, and A+ means exactly 100%.

Read the methodology →

Authenticated lane

External scans are honest about their limits. Run sscsb-action in your own CI to publish a record that sees what an outside scan cannot — through the same reviewed gate.

Install the Action →