SSCS Bootstrapper
Cprovisional

p4gs/sscsb-action

Scanned 2026-09-02 at 3f78b87de7b8 on main · sscsb 0.3.0 · methodology v1 · repository · scan run

Overall 70% · evidence coverage 66.7% · provisional

Commit integrity100%
Dependencies & SBOM100%
Provenance14.3%
SAST & CI hardening100%
Continuous posture100%

All controls

Raw sscsb verdicts and every reclassification are shown — transparency about what was and wasn't verifiable is the product. Phases: 1 = Commit integrity, 2 = Dependencies & SBOM, 3 = Provenance, 4 = SAST & CI hardening, 5 = Continuous posture.

PhaseControlVerdictDetail
1 secrets Pass raw: degraded

runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist

evidence
  • pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
  • trufflehog not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 3.95.9. Install: brew install trufflehog (Linuxbrew) or see Release binaries: https://github.com/trufflesecurity/trufflehog/releases (https://github.com/trufflesecurity/trufflehog)
  • gitleaks not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 8.30.1. Install: brew install gitleaks (Linuxbrew) or see Release binaries: https://github.com/gitleaks/gitleaks/releases (https://github.com/gitleaks/gitleaks)
1 commit-signing Unverified raw: pass

requires the local development environment; not observable in a repository scan

evidence
  • pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
  • 1 approved signer(s), 1 human
  • git config `gpg.format` unset — see docs/signing.md for YubiKey ed25519-sk setup
  • git config `user.signingkey` unset — see docs/signing.md for YubiKey ed25519-sk setup
  • git config `commit.gpgSign` unset — see docs/signing.md for YubiKey ed25519-sk setup
1 agent-signing out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
1 signing-model Unverified raw: degraded

requires the local development environment; not observable in a repository scan

evidence
  • human-local: incomplete — run `sscsb signing setup human-local`
  • agent-claude-code: incomplete — run `sscsb signing setup agent-claude-code`
  • cloud-claude: repo-side attribution is probeable and is not in place — an attestation cannot stand in for it
  • cloud-claude: github_app_installed: not attested — `sscsb signing setup cloud-claude --confirm`
  • github-web: vigilant_mode: not attested — `sscsb signing setup github-web --confirm`
  • github-web: phishing_resistant_mfa: not attested — `sscsb signing setup github-web --confirm`
  • codespaces: gpg_verification: not attested — `sscsb signing setup codespaces --confirm`
1 branch-protection Pass
evidence
  • main: required pull requests ✓
  • main: force-push blocking ✓
  • main: required signed commits ✓
  • main: required status checks ✓
  • main: deletion protection ✓
  • main: Scorecard — stale-review dismissal ✓
  • main: Scorecard gap — ≥1 required approving review off (needs a 2nd reviewer; a solo maintainer cannot self-approve — opt in with `sscsb harden branch-protection --require-reviews` once you have one)
  • main: Scorecard gap — code-owner review off (needs a 2nd reviewer; a solo maintainer cannot self-approve — opt in with `sscsb harden branch-protection --require-reviews` once you have one)
1 actions-audit Pass
evidence
  • all workflows pass (SHA-pinned, least-privilege)
1 gittuf out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
1 ai-trailers Unverified raw: pass

requires the local development environment; not observable in a repository scan

evidence
  • enforced by the commit-msg hook
  • pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
1 ai-dep-gate Unverified raw: pass

requires the local development environment; not observable in a repository scan

evidence
  • enforced by the commit-msg hook
  • pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
1 pr-template Pass
evidence
  • AI-provenance PR template installed (code/tests/deps/docs questions)
1 ai-receipts Unverified raw: degraded

requires the local development environment; not observable in a repository scan

evidence
  • receipts: `sscsb receipt create [commit]` → .sscsb/out/receipts/, `sscsb receipt verify <file>` recomputes the patch digest, re-reads the commit's AI trailers, and verifies any cosign bundle beside the receipt
  • cosign not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 3.1.1. Install: brew install cosign (Linuxbrew) or see Release binaries: https://github.com/sigstore/cosign/releases (https://github.com/sigstore/cosign)
2 sbom Pass raw: degraded

runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist

evidence
  • syft not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 1.46.0. Install: brew install syft (Linuxbrew) or see Release binaries: https://github.com/anchore/syft/releases (https://github.com/anchore/syft)
2 vuln-scan Pass raw: degraded

runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist

evidence
  • trivy not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.72.0. Install: brew install trivy (Linuxbrew) or see Release binaries: https://github.com/aquasecurity/trivy/releases (https://github.com/aquasecurity/trivy)
  • osv-scanner not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 2.4.0. Install: brew install osv-scanner (Linuxbrew) or see Release binaries: https://github.com/google/osv-scanner/releases (https://github.com/google/osv-scanner)
2 scorecard Unverified raw: degraded
evidence
  • .github/workflows/scorecard.yml installed
  • live Scorecard results could not be read (none published yet — the workflow runs on push to the default branch — or the code-scanning API refused) — posture unverified
2 renovate Pass
evidence
  • renovate.json5 installed (7 key(s))
2 package-trust Unverified raw: pass

requires the local development environment; not observable in a repository scan

evidence
  • new-package approval gate enforced in commit-msg hook
  • pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
  • approved baseline present (0 package(s))
  • registry existence validation ON for `sscsb deps check` and approvals (anti-slopsquat)
  • typosquat proximity heuristic ON for `sscsb deps check`, approvals, and the commit gate
2 bumblebee Unverified raw: degraded

requires the local development environment; not observable in a repository scan

evidence
  • bumblebee not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.1.2. Install: brew install bumblebee (Linuxbrew) or see Read-only endpoint inventory scanner (Go, zero dependencies). Release binaries: https://github.com/perplexityai/bumblebee/releases — exposur…
2 grype Unverified raw: degraded

requires the local development environment; not observable in a repository scan

evidence
  • grype not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.115.0. Install: brew install grype (Linuxbrew) or see Release binaries: https://github.com/anchore/grype/releases (https://github.com/anchore/grype)
2 socket-firewall out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
3 sigstore-signing Gap raw: disabled

evidence installed by the scanner's own init (.github/workflows/release-sign.yml) — absent from the repository

evidence
  • disabled in .sscsb/config.toml
3 slsa-provenance Gap raw: disabled

evidence installed by the scanner's own init (.github/workflows/release-slsa.yml) — absent from the repository

evidence
  • disabled in .sscsb/config.toml
3 github-attestations Gap raw: disabled

evidence installed by the scanner's own init (.github/workflows/release-attest.yml) — absent from the repository

evidence
  • disabled in .sscsb/config.toml
3 sbom-attestation Gap raw: disabled

evidence installed by the scanner's own init (.github/workflows/release-attest-sbom.yml) — absent from the repository

evidence
  • disabled in .sscsb/config.toml
3 model-signing out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
3 provenance-verify Gap raw: disabled

evidence installed by the scanner's own init (.github/workflows/deploy-gate.yml) — absent from the repository

evidence
  • disabled in .sscsb/config.toml
3 release-immutability out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
3 octo-sts Gap raw: disabled

evidence installed by the scanner's own init (.github/workflows/octo-sts-example.yml, .github/chainguard/sscsb-automation.sts.yaml) — absent from the repository

evidence
  • disabled in .sscsb/config.toml
3 harden-runner Pass
evidence
  • ci.yml: harden-runner present in job `self-test`
  • codeql.yml: harden-runner present in job `analyze`
  • sast-opengrep.yml: harden-runner present in job `opengrep`
  • sbom.yml: harden-runner present in job `sbom`
  • scorecard.yml: harden-runner present in job `analysis`
  • secrets-scan.yml: harden-runner present in job `trufflehog`
  • secrets-scan.yml: harden-runner present in job `gitleaks`
  • sscsb-scan.yml: harden-runner present in job `scan`
3 witness out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
4 sast Pass raw: degraded

runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist

evidence
  • engine: opengrep (rules: /home/runner/work/sscsb-action/sscsb-action/.sscsb/rules)
  • local ruleset present (1 file(s))
  • opengrep not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 1.25.0. Install: No Homebrew formula; install a pinned release binary: https://github.com/opengrep/opengrep/releases (https://github.com/opengrep/opengrep)
4 sighthound out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
4 codeql Pass
evidence
  • .github/workflows/codeql.yml installed (1 job(s))
4 fuzzing out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
4 workflow-audit-extended Pass
evidence
  • all workflows pass (SHA-pinned, least-privilege)
4 secure-repo out of scope Info

informational control — excluded from scoring

evidence
  • StepSecurity secure-repo is a web service (app.stepsecurity.io), not an action; run it against this repo to auto-generate hardening PRs. See docs/phase-4.md.
4 wait-for-secrets out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
5 dependency-track out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
5 guac out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
5 openvex Unverified raw: info

requires the local development environment; not observable in a repository scan

evidence
  • no OpenVEX documents in .sscsb/out — N/A for this repo until one is generated
  • generate: `sscsb vex create --vuln CVE-… --product pkg:… --status not_affected --justification …`
  • ingest: `sscsb scan --vex <file>` suppresses not_affected/fixed findings visibly
5 oras out of scope Info raw: disabled

optional control not enabled by this repository

evidence
  • disabled in .sscsb/config.toml
5 security-insights Pass
evidence
  • structurally valid — run `si validate` for full schema conformance
5 best-practices-badge Pass
evidence
  • .sscsb/best-practices-badge.md installed (present and non-empty; no machine-checkable structure — its substance is a human judgement sscsb does not assert)
5 osps-baseline Pass
evidence
  • .sscsb/osps-baseline.md installed (present and non-empty; no machine-checkable structure — its substance is a human judgement sscsb does not assert)
5 compliance-map out of scope Info raw: pass

informational control — excluded from scoring

evidence
  • map covers all 44 controls across SLSA/SSDF/CRA/Badge

About this record

This is an authenticated scan — published from the repository's own CI by the sscsb-action, through the same reviewed gate as every listing. Controls still marked unverified live in the development environment, which no CI scan can observe; that is a limit of the method, stated rather than hidden.