| 1 |
secrets |
Pass raw: degraded |
runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
- trufflehog not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 3.95.9. Install: brew install trufflehog (Linuxbrew) or see Release binaries: https://github.com/trufflesecurity/trufflehog/releases (https://github.com/trufflesecurity/trufflehog)
- gitleaks not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 8.30.1. Install: brew install gitleaks (Linuxbrew) or see Release binaries: https://github.com/gitleaks/gitleaks/releases (https://github.com/gitleaks/gitleaks)
|
| 1 |
commit-signing |
Unverified raw: pass |
requires the local development environment; not observable in a repository scan evidence- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
- 1 approved signer(s), 1 human
- git config `gpg.format` unset — see docs/signing.md for YubiKey ed25519-sk setup
- git config `user.signingkey` unset — see docs/signing.md for YubiKey ed25519-sk setup
- git config `commit.gpgSign` unset — see docs/signing.md for YubiKey ed25519-sk setup
|
| 1 |
agent-signing out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 1 |
signing-model |
Unverified raw: degraded |
requires the local development environment; not observable in a repository scan evidence- human-local: incomplete — run `sscsb signing setup human-local`
- agent-claude-code: incomplete — run `sscsb signing setup agent-claude-code`
- cloud-claude: repo-side attribution is probeable and is not in place — an attestation cannot stand in for it
- cloud-claude: github_app_installed: not attested — `sscsb signing setup cloud-claude --confirm`
- github-web: vigilant_mode: not attested — `sscsb signing setup github-web --confirm`
- github-web: phishing_resistant_mfa: not attested — `sscsb signing setup github-web --confirm`
- codespaces: gpg_verification: not attested — `sscsb signing setup codespaces --confirm`
|
| 1 |
branch-protection |
Pass |
evidence- main: required pull requests ✓
- main: force-push blocking ✓
- main: required signed commits ✓
- main: required status checks ✓
- main: deletion protection ✓
- main: Scorecard — stale-review dismissal ✓
- main: Scorecard gap — ≥1 required approving review off (needs a 2nd reviewer; a solo maintainer cannot self-approve — opt in with `sscsb harden branch-protection --require-reviews` once you have one)
- main: Scorecard gap — code-owner review off (needs a 2nd reviewer; a solo maintainer cannot self-approve — opt in with `sscsb harden branch-protection --require-reviews` once you have one)
|
| 1 |
actions-audit |
Pass |
evidence- all workflows pass (SHA-pinned, least-privilege)
|
| 1 |
gittuf out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 1 |
ai-trailers |
Unverified raw: pass |
requires the local development environment; not observable in a repository scan evidence- enforced by the commit-msg hook
- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
|
| 1 |
ai-dep-gate |
Unverified raw: pass |
requires the local development environment; not observable in a repository scan evidence- enforced by the commit-msg hook
- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
|
| 1 |
pr-template |
Pass |
evidence- AI-provenance PR template installed (code/tests/deps/docs questions)
|
| 1 |
ai-receipts |
Unverified raw: degraded |
requires the local development environment; not observable in a repository scan evidence- receipts: `sscsb receipt create [commit]` → .sscsb/out/receipts/, `sscsb receipt verify <file>` recomputes the patch digest, re-reads the commit's AI trailers, and verifies any cosign bundle beside the receipt
- cosign not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 3.1.1. Install: brew install cosign (Linuxbrew) or see Release binaries: https://github.com/sigstore/cosign/releases (https://github.com/sigstore/cosign)
|
| 2 |
sbom |
Pass raw: degraded |
runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence- syft not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 1.46.0. Install: brew install syft (Linuxbrew) or see Release binaries: https://github.com/anchore/syft/releases (https://github.com/anchore/syft)
|
| 2 |
vuln-scan |
Pass raw: degraded |
runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence- trivy not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.72.0. Install: brew install trivy (Linuxbrew) or see Release binaries: https://github.com/aquasecurity/trivy/releases (https://github.com/aquasecurity/trivy)
- osv-scanner not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 2.4.0. Install: brew install osv-scanner (Linuxbrew) or see Release binaries: https://github.com/google/osv-scanner/releases (https://github.com/google/osv-scanner)
|
| 2 |
scorecard |
Unverified raw: degraded |
evidence- .github/workflows/scorecard.yml installed
- live Scorecard results could not be read (none published yet — the workflow runs on push to the default branch — or the code-scanning API refused) — posture unverified
|
| 2 |
renovate |
Pass |
evidence- renovate.json5 installed (7 key(s))
|
| 2 |
package-trust |
Unverified raw: pass |
requires the local development environment; not observable in a repository scan evidence- new-package approval gate enforced in commit-msg hook
- pre-commit + commit-msg + pre-push shims installed, executable, and unmodified (core.hooksPath=.sscsb/hooks)
- approved baseline present (2 package(s))
- registry existence validation ON for `sscsb deps check` and approvals (anti-slopsquat)
- typosquat proximity heuristic ON for `sscsb deps check`, approvals, and the commit gate
|
| 2 |
bumblebee |
Unverified raw: degraded |
requires the local development environment; not observable in a repository scan evidence- bumblebee not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.1.2. Install: brew install bumblebee (Linuxbrew) or see Read-only endpoint inventory scanner (Go, zero dependencies). Release binaries: https://github.com/perplexityai/bumblebee/releases — exposur…
|
| 2 |
grype |
Unverified raw: degraded |
requires the local development environment; not observable in a repository scan evidence- grype not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 0.115.0. Install: brew install grype (Linuxbrew) or see Release binaries: https://github.com/anchore/grype/releases (https://github.com/anchore/grype)
|
| 2 |
socket-firewall |
Unverified raw: degraded |
requires the local development environment; not observable in a repository scan evidence- Socket Firewall CLI (sfw) not found — install per https://docs.socket.dev/docs/socket-firewall and wrap installs: `sfw npm install`, `sfw pip install`, `sfw cargo add`
- socket-firewall blocks known-malicious packages at install time (optional layer)
|
| 3 |
sigstore-signing |
Gap raw: disabled |
evidence installed by the scanner's own init (.github/workflows/release-sign.yml) — absent from the repository evidence- disabled in .sscsb/config.toml
|
| 3 |
slsa-provenance |
Gap raw: disabled |
evidence installed by the scanner's own init (.github/workflows/release-slsa.yml) — absent from the repository evidence- disabled in .sscsb/config.toml
|
| 3 |
github-attestations |
Gap raw: disabled |
evidence installed by the scanner's own init (.github/workflows/release-attest.yml) — absent from the repository evidence- disabled in .sscsb/config.toml
|
| 3 |
sbom-attestation |
Gap raw: disabled |
evidence installed by the scanner's own init (.github/workflows/release-attest-sbom.yml) — absent from the repository evidence- disabled in .sscsb/config.toml
|
| 3 |
model-signing out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 3 |
provenance-verify |
Gap raw: disabled |
evidence installed by the scanner's own init (.github/workflows/deploy-gate.yml) — absent from the repository evidence- disabled in .sscsb/config.toml
|
| 3 |
release-immutability out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 3 |
octo-sts |
Gap raw: disabled |
evidence installed by the scanner's own init (.github/workflows/octo-sts-example.yml, .github/chainguard/sscsb-automation.sts.yaml) — absent from the repository evidence- disabled in .sscsb/config.toml
|
| 3 |
harden-runner |
Pass |
evidence- ci.yml: harden-runner present in job `site`
- codeql.yml: harden-runner present in job `analyze`
- directory-ingest.yml: harden-runner present in job `ingest`
- directory-ingest.yml: harden-runner present in job `comment`
- directory-publish.yml: harden-runner present in job `publish`
- directory-scan.yml: harden-runner present in job `scan`
- directory-scan.yml: harden-runner present in job `comment`
- pages.yml: harden-runner present in job `build`
|
| 3 |
witness out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 4 |
sast |
Pass raw: degraded |
runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence- engine: opengrep (rules: /home/runner/work/p4gs.github.io/p4gs.github.io/.sscsb/rules)
- local ruleset present (1 file(s))
- opengrep not found on PATH — this control cannot run its underlying tool. Pinned known-good version: 1.25.0. Install: No Homebrew formula; install a pinned release binary: https://github.com/opengrep/opengrep/releases (https://github.com/opengrep/opengrep)
|
| 4 |
sighthound out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 4 |
codeql |
Pass |
evidence- .github/workflows/codeql.yml installed (1 job(s))
|
| 4 |
fuzzing out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 4 |
workflow-audit-extended |
Pass |
evidence- all workflows pass (SHA-pinned, least-privilege)
|
| 4 |
secure-repo out of scope |
Info |
informational control — excluded from scoring evidence- StepSecurity secure-repo is a web service (app.stepsecurity.io), not an action; run it against this repo to auto-generate hardening PRs. See docs/phase-4.md.
|
| 4 |
wait-for-secrets out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 5 |
dependency-track out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 5 |
guac out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 5 |
openvex |
Unverified raw: info |
requires the local development environment; not observable in a repository scan evidence- no OpenVEX documents in .sscsb/out — N/A for this repo until one is generated
- generate: `sscsb vex create --vuln CVE-… --product pkg:… --status not_affected --justification …`
- ingest: `sscsb scan --vex <file>` suppresses not_affected/fixed findings visibly
|
| 5 |
oras out of scope |
Info raw: disabled |
optional control not enabled by this repository evidence- disabled in .sscsb/config.toml
|
| 5 |
security-insights |
Pass |
evidence- structurally valid — run `si validate` for full schema conformance
|
| 5 |
best-practices-badge |
Pass |
evidence- .sscsb/best-practices-badge.md installed (present and non-empty; no machine-checkable structure — its substance is a human judgement sscsb does not assert)
|
| 5 |
osps-baseline |
Pass |
evidence- .sscsb/osps-baseline.md installed (present and non-empty; no machine-checkable structure — its substance is a human judgement sscsb does not assert)
|
| 5 |
compliance-map out of scope |
Info raw: pass |
informational control — excluded from scoring evidence- map covers all 44 controls across SLSA/SSDF/CRA/Badge
|