p4gs/sscsb-action
C provisionalOverall: 70% · evidence coverage: 66.7% · provisional
verified
needs attention
unverified — outside the math
Raw sscsb verdicts and every reclassification are shown — transparency about what was and wasn't verifiable is the product.
Phase 1 — Commit integrity
4 pass · 0 fail/gap · 5 unverified-
Pass
secretsraw: degradedrunner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-existevidence
- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
- trufflehog not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 3.95.9. Install: brew install trufflehog (Linuxbrew) or see Release binaries: https://github.com/trufflesecurity/trufflehog/releases (https://github.com/trufflesecurity/trufflehog)
- gitleaks not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 8.30.1. Install: brew install gitleaks (Linuxbrew) or see Release binaries: https://github.com/gitleaks/gitleaks/releases (https://github.com/gitleaks/gitleaks)
-
Unverified
commit-signingraw: passrequires the local development environment; not observable in a repository scanevidence
- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
- 1 approved signer(s), 1 human
- git config `gpg.format` unset — see docs/signing.md for YubiKey ed25519-sk setup
- git config `user.signingkey` unset — see docs/signing.md for YubiKey ed25519-sk setup
- git config `commit.gpgSign` unset — see docs/signing.md for YubiKey ed25519-sk setup
-
Info
agent-signingout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Unverified
signing-modelraw: degradedrequires the local development environment; not observable in a repository scanevidence
- human-local: incomplete — run `sscsb signing setup human-local`
- agent-claude-code: incomplete — run `sscsb signing setup agent-claude-code`
- cloud-claude: repo-side attribution is probeable and is not in place — an attestation cannot stand in for it
- cloud-claude: github_app_installed: not attested — `sscsb signing setup cloud-claude --confirm`
- github-web: vigilant_mode: not attested — `sscsb signing setup github-web --confirm`
- github-web: phishing_resistant_mfa: not attested — `sscsb signing setup github-web --confirm`
- codespaces: gpg_verification: not attested — `sscsb signing setup codespaces --confirm`
-
Pass
branch-protectionevidence
- main: required pull requests ✓
- main: force-push blocking ✓
- main: required signed commits ✓
- main: required status checks ✓
- main: deletion protection ✓
- main: Scorecard — stale-review dismissal ✓
- main: Scorecard gap — ≥1 required approving review off (needs a 2nd reviewer; a solo maintainer cannot self-approve — opt in with `sscsb harden branch-protection --require-reviews` once you have one)
- main: Scorecard gap — code-owner review off (needs a 2nd reviewer; a solo maintainer cannot self-approve — opt in with `sscsb harden branch-protection --require-reviews` once you have one)
-
Pass
actions-auditevidence
- all workflows pass (SHA-pinned, least-privilege)
-
Info
gittufout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Unverified
ai-trailersraw: passrequires the local development environment; not observable in a repository scanevidence
- enforced by the commit-msg hook
- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
-
Unverified
ai-dep-gateraw: passrequires the local development environment; not observable in a repository scanevidence
- enforced by the commit-msg hook
- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
-
Pass
pr-templateevidence
- AI-provenance PR template installed (code/tests/deps/docs questions)
-
Unverified
ai-receiptsraw: degradedrequires the local development environment; not observable in a repository scanevidence
- receipts: `sscsb receipt create [commit]` → .sscsb/out/receipts/, `sscsb receipt verify <file>` recomputes the patch digest, re-reads the commit's AI trailers, and verifies any cosign bundle beside the receipt
- cosign not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 3.1.1. Install: brew install cosign (Linuxbrew) or see Release binaries: https://github.com/sigstore/cosign/releases (https://github.com/sigstore/cosign)
Phase 2 — Dependencies & SBOM
3 pass · 0 fail/gap · 4 unverified-
Pass
sbomraw: degradedrunner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-existevidence
- syft not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 1.46.0. Install: brew install syft (Linuxbrew) or see Release binaries: https://github.com/anchore/syft/releases (https://github.com/anchore/syft)
-
Pass
vuln-scanraw: degradedrunner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-existevidence
- trivy not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.72.0. Install: brew install trivy (Linuxbrew) or see Release binaries: https://github.com/aquasecurity/trivy/releases (https://github.com/aquasecurity/trivy)
- osv-scanner not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 2.4.0. Install: brew install osv-scanner (Linuxbrew) or see Release binaries: https://github.com/google/osv-scanner/releases (https://github.com/google/osv-scanner)
-
Unverified
scorecardraw: degradedevidence
- .github/workflows/scorecard.yml installed
- live Scorecard results could not be read (none published yet — the workflow runs on push to the default branch — or the code-scanning API refused) — posture unverified
-
Pass
renovateevidence
- renovate.json5 installed (7 key(s))
-
Unverified
package-trustraw: passrequires the local development environment; not observable in a repository scanevidence
- new-package approval gate enforced in commit-msg hook
- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
- approved baseline present (0 package(s))
- registry existence validation ON for `sscsb deps check` and approvals (anti-slopsquat)
- typosquat proximity heuristic ON for `sscsb deps check`, approvals, and the commit gate
-
Unverified
bumblebeeraw: degradedrequires the local development environment; not observable in a repository scanevidence
- bumblebee not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.1.2. Install: brew install bumblebee (Linuxbrew) or see Read-only endpoint inventory scanner (Go, zero dependencies). Release binaries: https://github.com/perplexityai/bumblebee/releases — exposur…
-
Unverified
gryperaw: degradedrequires the local development environment; not observable in a repository scanevidence
- grype not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.115.0. Install: brew install grype (Linuxbrew) or see Release binaries: https://github.com/anchore/grype/releases (https://github.com/anchore/grype)
-
Info
socket-firewallout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
Phase 3 — Provenance
1 pass · 6 fail/gap · 0 unverified-
Gap
sigstore-signingraw: disabledevidence installed by the scanner's own init (.github/workflows/release-sign.yml) — absent from the repositoryevidence
- disabled in .sscsb/config.toml
-
Gap
slsa-provenanceraw: disabledevidence installed by the scanner's own init (.github/workflows/release-slsa.yml) — absent from the repositoryevidence
- disabled in .sscsb/config.toml
-
Gap
github-attestationsraw: disabledevidence installed by the scanner's own init (.github/workflows/release-attest.yml) — absent from the repositoryevidence
- disabled in .sscsb/config.toml
-
Gap
sbom-attestationraw: disabledevidence installed by the scanner's own init (.github/workflows/release-attest-sbom.yml) — absent from the repositoryevidence
- disabled in .sscsb/config.toml
-
Info
model-signingout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Gap
provenance-verifyraw: disabledevidence installed by the scanner's own init (.github/workflows/deploy-gate.yml) — absent from the repositoryevidence
- disabled in .sscsb/config.toml
-
Info
release-immutabilityout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Gap
octo-stsraw: disabledevidence installed by the scanner's own init (.github/workflows/octo-sts-example.yml, .github/chainguard/sscsb-automation.sts.yaml) — absent from the repositoryevidence
- disabled in .sscsb/config.toml
-
Pass
harden-runnerevidence
- ci.yml: harden-runner present in job `self-test`
- codeql.yml: harden-runner present in job `analyze`
- sast-opengrep.yml: harden-runner present in job `opengrep`
- sbom.yml: harden-runner present in job `sbom`
- scorecard.yml: harden-runner present in job `analysis`
- secrets-scan.yml: harden-runner present in job `trufflehog`
- secrets-scan.yml: harden-runner present in job `gitleaks`
- sscsb-scan.yml: harden-runner present in job `scan`
-
Info
witnessout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
Phase 4 — SAST & CI hardening
3 pass · 0 fail/gap · 0 unverified-
Pass
sastraw: degradedrunner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-existevidence
- engine: opengrep (rules: /home/runner/work/sscsb-action/sscsb-action/.sscsb/rules)
- local ruleset present (1 file(s))
- opengrep not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 1.25.0. Install: No Homebrew formula; install a pinned release binary: https://github.com/opengrep/opengrep/releases (https://github.com/opengrep/opengrep)
-
Info
sighthoundout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Pass
codeqlevidence
- .github/workflows/codeql.yml installed (1 job(s))
-
Info
fuzzingout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Pass
workflow-audit-extendedevidence
- all workflows pass (SHA-pinned, least-privilege)
-
Info
secure-repoout of scopeinformational control — excluded from scoringevidence
- StepSecurity secure-repo is a web service (app.stepsecurity.io), not an action; run it against this repo to auto-generate hardening PRs. See docs/phase-4.md.
-
Info
wait-for-secretsout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
Phase 5 — Continuous posture
3 pass · 0 fail/gap · 1 unverified-
Info
dependency-trackout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Info
guacout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Unverified
openvexraw: inforequires the local development environment; not observable in a repository scanevidence
- no OpenVEX documents in .sscsb/out — N/A for this repo until one is generated
- generate: `sscsb vex create --vuln CVE-… --product pkg:… --status not_affected --justification …`
- ingest: `sscsb scan --vex <file>` suppresses not_affected/fixed findings visibly
-
Info
orasout of scope raw: disabledoptional control not enabled by this repositoryevidence
- disabled in .sscsb/config.toml
-
Pass
security-insightsevidence
- structurally valid — run `si validate` for full schema conformance
-
Pass
best-practices-badgeevidence
- .sscsb/best-practices-badge.md installed (present and non-empty; no machine-checkable structure — its substance is a human judgement sscsb does not assert)
-
Pass
osps-baselineevidence
- .sscsb/osps-baseline.md installed (present and non-empty; no machine-checkable structure — its substance is a human judgement sscsb does not assert)
-
Info
compliance-mapout of scope raw: passinformational control — excluded from scoringevidence
- map covers all 44 controls across SLSA/SSDF/CRA/Badge
Improve this score
This record came through the authenticated lane — published by the repository's own CI via the sscsb-action. Amber and hatched links above are the work list: adopt the flagged controls, re-run the action, and the next record replaces this one.