p4gs/sscsb-action
CI · verified
clears the 75% floorThe grade is not provisional. How coverage is scored →
Defences found, by attack group
This lists defences the scan found, not weaknesses it found. A missing defence is not a break-in, and a full set of checks is not safety: nine groups and 54 checks do not cover everything. What the nine groups are →
-
A1 Poisoned commit
All answered checks passed
Every answered check passed — 5 of 5. 2 more produced no answer.
No answer
signing-model,scorecard— 1 of these only a maintainer's own machine can answer Every sscsb check here that produced an answer passed. That is not the same as being safe from this group. -
A2 Stolen publisher identity
All answered checks passed
Every answered check passed — 6 of 6. 1 more produced no answer.
No answer
signing-model— all of these only a maintainer's own machine can answer Every sscsb check here that produced an answer passed. That is not the same as being safe from this group. - A3 Look-alike or invented package All answered checks passed Every check passed — 2 of 2. Every sscsb check here that produced an answer passed. That is not the same as being safe from this group.
-
A4 A real dependency turns hostile, or stays broken
All answered checks passed
Every answered check passed — 8 of 8. 3 more produced no answer.
No answer
scorecard,bumblebee,openvex— 2 of these only a maintainer's own machine can answer Every sscsb check here that produced an answer passed. That is not the same as being safe from this group. -
A5 Hijacked build pipeline
All answered checks passed
Every answered check passed — 9 of 9. 1 more produced no answer.
No answer
scorecardEvery sscsb check here that produced an answer passed. That is not the same as being safe from this group. -
A6 Compromised developer environment
All answered checks passed
Every answered check passed — 4 of 4. 2 more produced no answer.
No answer
signing-model,bumblebee— all of these only a maintainer's own machine can answer Every sscsb check here that produced an answer passed. That is not the same as being safe from this group. - A7 Leaked credential All answered checks passed Every check passed — 5 of 5. Every sscsb check here that produced an answer passed. That is not the same as being safe from this group.
- A8 A flaw in the code you wrote All answered checks passed Every check passed — 3 of 3. Every sscsb check here that produced an answer passed. That is not the same as being safe from this group.
- A9 Untrustworthy delivery All answered checks passed Every check passed — 7 of 7. Every sscsb check here that produced an answer passed. That is not the same as being safe from this group.
These checks do not stop an attack. They let an outsider tell what a project already does, and where to report a problem. They are not in the list above:
best-practices-badge, compliance-map, osps-baseline, publish-targets, secure-repo, security-insights.
Authenticated scan — signature verified
Produced in the repository's own CI and
keyless-signed there. Before listing it, the directory verified the Sigstore bundle
against the certificate identity https://github.com/p4gs/sscsb-action/.github/workflows/sscsb-scan.yml@refs/heads/main bound to commit c7deeef08747 on 2026-09-03.
The repository, the workflow path and the default branch are burned into that
certificate by GitHub's OIDC issuer. The record does not assert them.
Re-verify it yourself: scan-record.json · signature bundle
Local scan — signature verified
A maintainer ran sscsb on their own machine and signed the record
with their git signing key. The directory verified that detached SSH signature with
ssh-keygen -Y verify against .sscsb/policy/allowed_signers
fetched from this repository at commit
f37f780cb0f2 — committed content the
submitter does not supply. Verifying principal
10093271+p4gs@users.noreply.github.com (SHA256:prXatGO56nl8Or4JdDSzIIcj8hZE1jBxnFaXZOnAPDQ) on 2026-09-11.
What that proves, exactly: a holder of a key this repository commits as an approved signer asserts this result at that commit. Nothing more. It is weaker than an authenticated scan, which proves the repository's own CI produced the record.
It contributed 6 controls: commit-signing, ai-trailers, ai-dep-gate, ai-receipts, package-trust, grype. Every other class comes from the repository-observable record. A local scan never
overturns one, and never widens the scope it is measured against.
Re-verify it yourself: scan-record.local.json · detached signature
ssh-keygen -Y verify -f allowed_signers \
-I "10093271+p4gs@users.noreply.github.com" -n sscsb-scan-record \
-s scan-record.local.json.sig < scan-record.local.json
What the evidence merge found
The local record describes commit f37f780cb0f2, while the repository scan on this listing describes c7deeef08747. Its local-environment rows may predate the code above them.
Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 87.1% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 86.1%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number.
All controls
Raw sscsb verdicts and every reclassification are shown. Being transparent about what was and was not verifiable is the product. The checks run in six phases, named on the band above each group.
- Note 1runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist
- Note 2resolved by a signed local scan: this control lives in the development environment, so a workstation record signed by a key this repository commits in .sscsb/policy/allowed_signers is the only evidence that can exist for it
- Note 3requires the local development environment; not observable in a repository scan
| Control | Verdict | Detail |
|---|---|---|
| Phase 1 — Commit integrity11 checks | ||
secrets |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's… note 1evidence (3)
|
commit-signing |
Pass raw: pass | resolved by a signed local scan… note 2evidence (6)
|
agent-signing out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
signing-model |
Unverified raw: degraded | requires the local development environment… note 3evidence (7)
|
branch-protection |
Pass | evidence (8)
|
actions-audit |
Pass | evidence (1)
|
gittuf out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
ai-trailers |
Pass raw: pass | resolved by a signed local scan… note 2evidence (2)
|
ai-dep-gate |
Pass raw: pass | resolved by a signed local scan… note 2evidence (2)
|
pr-template |
Pass | evidence (1)
|
ai-receipts |
Pass raw: pass | resolved by a signed local scan… note 2evidence (2)
|
| Phase 2 — Dependencies8 checks | ||
sbom |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's… note 1evidence (1)
|
vuln-scan |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's… note 1evidence (2)
|
scorecard |
Unverified raw: degraded | no lane produced a verdict for this control — an unperformed check is never a verdictevidence (2)
|
renovate |
Pass | evidence (1)
|
package-trust |
Pass raw: pass | resolved by a signed local scan… note 2evidence (5)
|
bumblebee |
Unverified raw: degraded | requires the local development environment… note 3evidence (1)
|
grype |
Pass raw: pass | resolved by a signed local scan… note 2evidence (1)
|
socket-firewall out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
| Phase 3 — Build receipts10 checks | ||
sigstore-signing |
Pass | evidence (2)
|
slsa-provenance |
Pass | evidence (2)
|
github-attestations |
Pass | evidence (2)
|
sbom-attestation |
Pass | evidence (2)
|
model-signing out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
provenance-verify |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's… note 1evidence (5)
|
release-immutability |
Pass | evidence (1)
|
octo-sts |
Pass | evidence (2)
|
harden-runner |
Pass | evidence (8)
|
witness out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
| Phase 4 — Code & build hardening7 checks | ||
sast |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's… note 1evidence (3)
|
sighthound out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
codeql |
Pass | evidence (1)
|
fuzzing out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
workflow-audit-extended |
Pass | evidence (1)
|
secure-repo out of scope |
Info | informational control — excluded from scoring |
wait-for-secrets out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
| Phase 5 — Ongoing posture8 checks | ||
dependency-track out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
guac out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
openvex |
Unverified raw: info | requires the local development environment… note 3evidence (3)
|
oras out of scope |
Info raw: disabled | optional control not enabled by this repositoryevidence (1)
|
security-insights |
Pass | evidence (1)
|
best-practices-badge |
Pass | evidence (1)
|
osps-baseline |
Pass | evidence (1)
|
compliance-map out of scope |
Info raw: pass | informational control — excluded from scoring |
| Phase 6 — Distribution & publishingno checks in this record | ||