PUBLIC RECORD · 3 LISTED
Scan directory
Repositories scanned with sscsb, scored by the
published methodology. A maintainer reviewed every
listing before it appeared. Type any owner/repo to search the record — or
to put one that is not in it yet into the scan queue.
No record for this repository yet. Request an unauthenticated sscsb scan. A maintainer reviews every record before it enters the directory.
| Repository | Grade | Passed | Answered | Verdicts | Source | Scanned |
|---|---|---|---|---|---|---|
|
p4gs/sscs-bootstrapper
No description published.
2 notes on this recordThe local record describes commit 3cb129084db2, while the repository scan on this listing describes c8a23493ec0c. Its local-environment rows may predate the code above them. Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 90.9% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 89.5%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number. |
A+ | 100% | 90.9% | 30003 | signed CI | 2026-09-03 |
|
p4gs/p4gs.github.io
Sensible Security tools — tools.sensiblesecurity.xyz (landing, sscsb site + public scan directory)
2 notes on this recordThe local record describes commit 710cf8e461f2, while the repository scan on this listing describes 3ab6bf98504b. Its local-environment rows may predate the code above them. Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 87.1% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 86.1%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number. |
A+ | 100% | 87.1% | 27004 | signed CI | 2026-09-03 |
|
p4gs/sscsb-action
Run sscsb supply-chain-security scans in your own CI — authenticated scan records for tools.sensiblesecurity.xyz/sscsb/
2 notes on this recordThe local record describes commit f37f780cb0f2, while the repository scan on this listing describes c7deeef08747. Its local-environment rows may predate the code above them. Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 87.1% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 86.1%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number. |
A+ | 100% | 87.1% | 27004 | signed CI | 2026-09-03 |
Nothing in the record matches
. Three repositories are listed so far, and a repository
that is not one of them has simply not been scanned — it is not a verdict about it.
Type a full owner/repo and the scan queue opens above; or
clear the filter to see every listing.
What the columns mean
Two numbers ride with every listing: how many checks passed, and how many produced an answer at all. A low second number is not a mark against the project — it means the scan could not see far enough. Each listing says which checks went unanswered, and why (how that is checked).
- answered checks
- the checks that produced a pass, a fail, or a missing-defence result
- evidence coverage
- how many of the checks produced a yes-or-no answer at all
- provisional
- the grade stands, but too much went unchecked to treat it as settled
- unverified
- nobody could answer this check — which is not the same as failing it
- gap
- the defence was looked for and not found
- evidence source
- who ran the scan, and therefore how much of the project they could see