Honest arithmetic
A check that could not run is a third state. It is shown as a dashed ring and left out of the sums. An unanswered check is never a verdict, and A+ means every answered check passed.
How scoring works →SUPPLY-CHAIN SECURITY · SCANNED IN PUBLIC
Every listing here is a public record of one scan of one commit.
Already listed.
Open the listing →Not on file yet. Ask for a scan — a person reviews every result before it appears.
Already listedp4gs/p4gs.github.iop4gs/sscs-bootstrapperp4gs/sscsb-action
Best scoring
The listings that passed the most of what could be checked.
A "best scoring" list needs 12 listings and more than one grade among them. Otherwise it is just a tie, broken by a number this site says not to hold against anyone. There are 3 listings and 1 grade so far.
Browse every listing →Freshest evidence
A scan is a snapshot of one commit. These are the newest.
Every listing here was scanned by the same scheduled run, minutes apart, so ordering them by date would be ordering noise. This fills in once projects run their own scans on their own schedules.
Browse every listing →Across every listing
The checks that most often have no answer here — and why.
openvex
3 of 3
only a maintainer's own machine can answer this
scorecard
3 of 3
no source could answer it
signing-model
3 of 3
only a maintainer's own machine can answer this
bumblebee
2 of 3
only a maintainer's own machine can answer this
3 of these 4 describe a developer's own machine. No scan from outside can see them — a maintainer answers them by running the scan themselves and signing the result. How that is checked →
What the checks are for
Every check defends against at least one of these — or says plainly that it defends against none, and only tells outsiders what a project does.
Each one, with what it looked like when it happened →brew install p4gs/p4gs/sscsb
A check that could not run is a third state. It is shown as a dashed ring and left out of the sums. An unanswered check is never a verdict, and A+ means every answered check passed.
How scoring works →A scan from outside sees only what anyone can see. Run sscsb in your own build and it sees the rest. It then signs the result, so the signature proves where the record came from.
Install the Action →About a dozen checks describe a developer's own laptop, where no scan can reach. A maintainer answers those by running the scan there and signing it. The key they sign with is one the project already publishes.
How that is checked →