sscsb

p4gs/p4gs.github.io

C provisional

https://github.com/p4gs/p4gs.github.io · scanned 2026-09-02 at 852746a678eb on main · sscsb 0.3.0 · methodology v1 · scan run · external

Overall: 70% · evidence coverage: 64.5% · provisional

verified needs attention unverified — outside the math

Raw sscsb verdicts and every reclassification are shown — transparency about what was and wasn't verifiable is the product.

Phase 1 — Commit integrity

4 pass · 0 fail/gap · 5 unverified
100%

Phase 2 — Dependencies & SBOM

3 pass · 0 fail/gap · 5 unverified
100%

Phase 3 — Provenance

1 pass · 6 fail/gap · 0 unverified
14.3%

Phase 4 — SAST & CI hardening

3 pass · 0 fail/gap · 0 unverified
100%

Phase 5 — Continuous posture

3 pass · 0 fail/gap · 1 unverified
100%

Improve this score

This is an external scan — controls that live in the development environment show as unverified, and GitHub-side checks ran with public-only visibility. Repo maintainers can publish an authenticated scan by running the sscsb-action in their own CI.