SSCS Bootstrapper

A field manual for the software supply chain

Security you can actually verify, not just claim.

Forty-four controls across five phases — from the commit boundary to continuous posture — bootstrapped in one command and reported with a bluntness your auditor will find unfamiliar. An unperformed check is never a verdict.

brew install p4gs/p4gs/sscsb
Read the methodology

The commit is the boundary

Secrets blocked at the hook, humans sign on protected branches, and AI involvement is declared in trailers — not discovered in an incident review.

Evidence, then verdicts

SBOMs, dual scanners, keyless signatures and SLSA provenance — every claim bound to a digest something else can check.

A directory with a spine

Public grades under a versioned methodology that refuses to count evidence the scanner created — or checks that never ran.

From the directory

p4gs/sscs-bootstrapper — the tool, scanned by itself.

81.8% overall · coverage 73.3% · provisional · methodology v1

B