A field manual for the software supply chain
Security you can actually verify, not just claim.
Forty-four controls across five phases — from the commit boundary to continuous posture — bootstrapped in one command and reported with a bluntness your auditor will find unfamiliar. An unperformed check is never a verdict.
brew install p4gs/p4gs/sscsb
Read the methodology
The commit is the boundary
Secrets blocked at the hook, humans sign on protected branches, and AI involvement is declared in trailers — not discovered in an incident review.
Evidence, then verdicts
SBOMs, dual scanners, keyless signatures and SLSA provenance — every claim bound to a digest something else can check.
A directory with a spine
Public grades under a versioned methodology that refuses to count evidence the scanner created — or checks that never ran.
From the directory
p4gs/sscs-bootstrapper — the tool, scanned by itself.