SSCSB

Supply-chain scans, on the record

Methodv2 Schemav1

The directory

Every scan on the record

Repositories scanned with sscsb, scored by the published methodology. A person reviewed every listing before it appeared here.

GradeRepositoryPhasesEvidence sourceScanned
A+ p4gs/sscs-bootstrapper 100% passed · coverage 90.9% · clears the 75% floor
Mergelocal 3cb129084db2 ≠ scan c8a23493ec0c · self-reported A+ 100% vs DIRECTORY A+ 100%

The local record describes commit 3cb129084db2, while the repository scan on this listing describes c8a23493ec0c. Its local-environment rows may predate the code above them.

Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 90.9% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 89.5%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number.

CI · verified+local 8 2026-09-03
A+ p4gs/p4gs.github.io Sensible Security tools — tools.sensiblesecurity.xyz (landing, sscsb site + public scan directory) 100% passed · coverage 87.1% · clears the 75% floor
Mergelocal 710cf8e461f2 ≠ scan 3ab6bf98504b · self-reported A+ 100% vs DIRECTORY A+ 100%

The local record describes commit 710cf8e461f2, while the repository scan on this listing describes 3ab6bf98504b. Its local-environment rows may predate the code above them.

Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 87.1% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 86.1%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number.

CI · verified+local 7 2026-09-03
A+ p4gs/sscsb-action Run sscsb supply-chain-security scans in your own CI — authenticated scan records for tools.sensiblesecurity.xyz/sscsb/ 100% passed · coverage 87.1% · clears the 75% floor
Mergelocal f37f780cb0f2 ≠ scan c7deeef08747 · self-reported A+ 100% vs DIRECTORY A+ 100%

The local record describes commit f37f780cb0f2, while the repository scan on this listing describes c7deeef08747. Its local-environment rows may predate the code above them.

Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 87.1% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 86.1%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number.

CI · verified+local 6 2026-09-03
Key pass fail / gap unverified — nobody could answer this check — which is not the same as failing it Local · signed a maintainer ran this on their own machine and signed it — the only evidence that can exist for the checks only they can see +local n n controls on that listing were settled by a maintainer's signed local scan

PhasesP1 commits · P2 deps · P3 receipts · P4 hardening · P5 posture · P6 publishing

Two numbers ride with every listing. One is how many of the answered checks — the checks that produced a pass, a fail, or a missing-defence result passed. The other is evidence coverage — how many of the checks produced a yes-or-no answer at all. A low second number is not a mark against the project: it means the scan could not see far enough. Each listing says which checks went unanswered, and why. Where a letter is provisional — the grade stands, but too much went unchecked to treat it as settled, that is the reason. A check that went unanswered is unverified — nobody could answer this check — which is not the same as failing it; one that was looked for and not found is a gap — the defence was looked for and not found. The evidence source — who ran the scan, and therefore how much of the project they could see column says who ran the scan (how that is checked).