p4gs/sscsb-action
✓ verified100% of the answered checks passed · 87.1% of the checks were answered at all
Defences found, by attack group
This lists defences the scan found, not weaknesses it found. A missing defence is not a break-in, and a full set of checks is not safety: nine groups and 54 checks do not cover everything. What the nine groups are →
-
A1 Poisoned commit
All answered checks passed
Every answered check passed — 5 of 5. 2 more produced no answer.
No answer
signing-model,scorecard— 1 of these only a maintainer's own machine can answer Every sscsb check here that produced an answer passed. That is not the same as being safe from this group. -
A2 Stolen publisher identity
All answered checks passed
Every answered check passed — 6 of 6. 1 more produced no answer.
No answer
signing-model— all of these only a maintainer's own machine can answer Every sscsb check here that produced an answer passed. That is not the same as being safe from this group. - A3 Look-alike or invented package All answered checks passed Every check passed — 2 of 2. Every sscsb check here that produced an answer passed. That is not the same as being safe from this group.
-
A4 A real dependency turns hostile, or stays broken
All answered checks passed
Every answered check passed — 8 of 8. 3 more produced no answer.
No answer
scorecard,bumblebee,openvex— 2 of these only a maintainer's own machine can answer Every sscsb check here that produced an answer passed. That is not the same as being safe from this group. -
A5 Hijacked build pipeline
All answered checks passed
Every answered check passed — 9 of 9. 1 more produced no answer.
No answer
scorecardEvery sscsb check here that produced an answer passed. That is not the same as being safe from this group. -
A6 Compromised developer environment
All answered checks passed
Every answered check passed — 4 of 4. 2 more produced no answer.
No answer
signing-model,bumblebee— all of these only a maintainer's own machine can answer Every sscsb check here that produced an answer passed. That is not the same as being safe from this group. - A7 Leaked credential All answered checks passed Every check passed — 5 of 5. Every sscsb check here that produced an answer passed. That is not the same as being safe from this group.
- A8 A flaw in the code you wrote All answered checks passed Every check passed — 3 of 3. Every sscsb check here that produced an answer passed. That is not the same as being safe from this group.
- A9 Untrustworthy delivery All answered checks passed Every check passed — 7 of 7. Every sscsb check here that produced an answer passed. That is not the same as being safe from this group.
These checks do not stop an attack. They let an outsider tell what a project already does, and where to report a problem. They are not in the list above:
best-practices-badge, compliance-map, osps-baseline, publish-targets, secure-repo, security-insights.
Authenticated scan — signature verified
This record was produced in the repository's own CI and
keyless-signed there. Before listing it, the directory verified the Sigstore
bundle against the certificate identity
https://github.com/p4gs/sscsb-action/.github/workflows/sscsb-scan.yml@refs/heads/main bound to commit c7deeef08747 on 2026-09-03.
The repository, workflow path, and default branch are burned into that certificate
by GitHub's OIDC issuer, not asserted by the record.
Re-verify it yourself: scan-record.json · signature bundle
cosign verify-blob scan-record.json --bundle scan-record.json.sigstore.json \
--certificate-identity "https://github.com/p4gs/sscsb-action/.github/workflows/sscsb-scan.yml@refs/heads/main" \
--certificate-oidc-issuer https://token.actions.githubusercontent.com
Local scan — signature verified
A maintainer ran sscsb on their own machine and signed the record
with their git signing key. The directory verified that detached SSH signature with
ssh-keygen -Y verify against
.sscsb/policy/allowed_signers fetched from this repository at
commit f37f780cb0f2 — committed content the
submitter does not supply. The verifying principal was
10093271+p4gs@users.noreply.github.com (SHA256:prXatGO56nl8Or4JdDSzIIcj8hZE1jBxnFaXZOnAPDQ) on 2026-09-11.
What that proves, exactly: a holder of a key this repository commits as an approved signer asserts this result at that commit. Nothing more. It is attributable and auditable, and it is weaker than an authenticated scan, which proves the repository's own CI produced the record.
It contributed 6 controls: commit-signing, ai-trailers, ai-dep-gate, ai-receipts, package-trust, grype. Every other class on this page comes from the repository-observable
record above; a local scan may never overturn one, and may never widen the
scope it is measured against.
Re-verify it yourself: scan-record.local.json · detached signature
curl -sO https://raw.githubusercontent.com/p4gs/sscsb-action/f37f780cb0f236685090d7d92fe6ab00f381805a/.sscsb/policy/allowed_signers
ssh-keygen -Y verify -f allowed_signers \
-I "10093271+p4gs@users.noreply.github.com" -n sscsb-scan-record \
-s scan-record.local.json.sig < scan-record.local.json
What the evidence merge found
The local record describes commit f37f780cb0f2, while the repository scan on this listing describes c7deeef08747. Its local-environment rows may predate the code above them.
Two scores are on this page and only one of them is ours. The grade and coverage shown here — A+, 100%, coverage 87.1% — are the DIRECTORY's, computed from every evidence source it holds under the published methodology. The signed local record linked below carries its own score block (A+, 100%, coverage 86.1%): that is the SUBMITTER's self-report, computed on their machine over the controls that machine had in scope. It is republished byte-identically because the signature covers those exact bytes, not because the directory endorses the number.
All controls
Raw sscsb verdicts and every reclassification are shown — transparency about what was and wasn't verifiable is the product. Phases: 1 = Commit integrity, 2 = Dependencies, 3 = Build receipts, 4 = Code & build hardening, 5 = Ongoing posture, 6 = Distribution & publishing.
| Phase | Control | Verdict | Detail |
|---|---|---|---|
| 1 | secrets |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence
|
| 1 | commit-signing |
Pass raw: pass | resolved by a signed local scan: this control lives in the development environment, so a workstation record signed by a key this repository commits in .sscsb/policy/allowed_signers is the only evidence that can exist for it evidence
|
| 1 | agent-signing out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 1 | signing-model |
Unverified raw: degraded | requires the local development environment; not observable in a repository scan evidence
|
| 1 | branch-protection |
Pass | evidence
|
| 1 | actions-audit |
Pass | evidence
|
| 1 | gittuf out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 1 | ai-trailers |
Pass raw: pass | resolved by a signed local scan: this control lives in the development environment, so a workstation record signed by a key this repository commits in .sscsb/policy/allowed_signers is the only evidence that can exist for it evidence
|
| 1 | ai-dep-gate |
Pass raw: pass | resolved by a signed local scan: this control lives in the development environment, so a workstation record signed by a key this repository commits in .sscsb/policy/allowed_signers is the only evidence that can exist for it evidence
|
| 1 | pr-template |
Pass | evidence
|
| 1 | ai-receipts |
Pass raw: pass | resolved by a signed local scan: this control lives in the development environment, so a workstation record signed by a key this repository commits in .sscsb/policy/allowed_signers is the only evidence that can exist for it evidence
|
| 2 | sbom |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence
|
| 2 | vuln-scan |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence
|
| 2 | scorecard |
Unverified raw: degraded | no lane produced a verdict for this control — an unperformed check is never a verdict evidence
|
| 2 | renovate |
Pass | evidence
|
| 2 | package-trust |
Pass raw: pass | resolved by a signed local scan: this control lives in the development environment, so a workstation record signed by a key this repository commits in .sscsb/policy/allowed_signers is the only evidence that can exist for it evidence
|
| 2 | bumblebee |
Unverified raw: degraded | requires the local development environment; not observable in a repository scan evidence
|
| 2 | grype |
Pass raw: pass | resolved by a signed local scan: this control lives in the development environment, so a workstation record signed by a key this repository commits in .sscsb/policy/allowed_signers is the only evidence that can exist for it evidence
|
| 2 | socket-firewall out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 3 | sigstore-signing |
Pass | evidence
|
| 3 | slsa-provenance |
Pass | evidence
|
| 3 | github-attestations |
Pass | evidence
|
| 3 | sbom-attestation |
Pass | evidence
|
| 3 | model-signing out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 3 | provenance-verify |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence
|
| 3 | release-immutability |
Pass | evidence
|
| 3 | octo-sts |
Pass | evidence
|
| 3 | harden-runner |
Pass | evidence
|
| 3 | witness out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 4 | sast |
Pass raw: degraded | runner-tool availability is the scanner's environment, not the repository's; all registered artifacts pre-exist evidence
|
| 4 | sighthound out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 4 | codeql |
Pass | evidence
|
| 4 | fuzzing out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 4 | workflow-audit-extended |
Pass | evidence
|
| 4 | secure-repo out of scope |
Info | informational control — excluded from scoring |
| 4 | wait-for-secrets out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 5 | dependency-track out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 5 | guac out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 5 | openvex |
Unverified raw: info | requires the local development environment; not observable in a repository scan evidence
|
| 5 | oras out of scope |
Info raw: disabled | optional control not enabled by this repository evidence
|
| 5 | security-insights |
Pass | evidence
|
| 5 | best-practices-badge |
Pass | evidence
|
| 5 | osps-baseline |
Pass | evidence
|
| 5 | compliance-map out of scope |
Info raw: pass | informational control — excluded from scoring |