Skip to content
sscsb

PUBLIC RECORD · 3 LISTED

Scan directory

Repositories scanned with sscsb, scored by the published methodology. A maintainer reviewed every listing before it appeared. Type any owner/repo to search the record — or to put one that is not in it yet into the scan queue.

passed there, not working looked for, not found nobody could answer — never counted informational — never scored
Repository Grade Passed Answered Verdicts Source Scanned
p4gs/sscs-bootstrapper
No description published.
2 notes on this record

The local record describes commit 3cb129084db2, while the repository scan on this listing describes c8a23493ec0c. Its local-environment rows may predate the code above them.

Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 90.9% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 89.5%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number.

A+ 100% 90.9% 30003 signed CI+ local 8 2026-09-03
p4gs/p4gs.github.io
Sensible Security tools — tools.sensiblesecurity.xyz (landing, sscsb site + public scan directory)
2 notes on this record

The local record describes commit 710cf8e461f2, while the repository scan on this listing describes 3ab6bf98504b. Its local-environment rows may predate the code above them.

Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 87.1% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 86.1%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number.

A+ 100% 87.1% 27004 signed CI+ local 7 2026-09-03
p4gs/sscsb-action
Run sscsb supply-chain-security scans in your own CI — authenticated scan records for tools.sensiblesecurity.xyz/sscsb/
2 notes on this record

The local record describes commit f37f780cb0f2, while the repository scan on this listing describes c7deeef08747. Its local-environment rows may predate the code above them.

Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 87.1% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 86.1%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number.

A+ 100% 87.1% 27004 signed CI+ local 6 2026-09-03
passed there, not working looked for, not found nobody could answer — never counted informational — never scored

What the columns mean

Two numbers ride with every listing: how many checks passed, and how many produced an answer at all. A low second number is not a mark against the project — it means the scan could not see far enough. Each listing says which checks went unanswered, and why (how that is checked).

answered checks
the checks that produced a pass, a fail, or a missing-defence result
evidence coverage
how many of the checks produced a yes-or-no answer at all
provisional
the grade stands, but too much went unchecked to treat it as settled
unverified
nobody could answer this check — which is not the same as failing it
gap
the defence was looked for and not found
evidence source
who ran the scan, and therefore how much of the project they could see