Live verification
Your supply chain,
on instruments.
44 controls across five phases, verified with evidence and reported without spin. A check that couldn't run reads as unverified — never as a pass.
$ brew install p4gs/p4gs/sscsb
Open the directory
3 repositories on the public record
Commit integrity100%
Dependencies100%
Provenance50%
SAST & CI100%
Posture100%
overall 81.8% · coverage 73.3% · provisional · scanned 2026-09-01
44
verifiable controls
2
scan lanes — external & authenticated
A+
reserved for exactly 100%
0
unverified checks counted — ever
LANE · EXTERNAL
The public directory
Every listed repository was scanned with sscsb itself and scored by a published, versioned methodology. Evidence the scanner created never counts, and checks that couldn't run stay hatched on the meter — shown, not spun.
LANE · AUTHENTICATED
Authenticated scans
External scans are honest about their limits. Run
sscsb-action in your own CI to publish a record that sees what
an outside scan cannot — through the same reviewed gate.