Skip to main content

sscsb

Bootstrap and verify software supply chain security in a git repository using the `sscsb` CLI — secret scanning, commit signing policy, SBOMs, vulnerability scanning, SAST, dependency trust, SLSA provenance, and continuous posture, as 44 individually toggleable controls across five phases. USE WHEN harden this repo, supply chain security, SSCS, secret scanning, commit signing, SBOM, vulnerability scan, dependency trust, typosquat, SLSA provenance, sigstore, cosign, OpenSSF Scorecard, OpenVEX, SAST, branch protection, pin GitHub Actions, is this repo secure, set up security controls, sscsb, security baseline for a project. NOT FOR offensive security, pentesting, or exploit development; NOT FOR runtime threat detection, SIEM, or EDR; NOT FOR designing or implementing cryptographic primitives; NOT FOR general code review.

Jump to install

Source facts

Repository
p4gs/sscs-bootstrapper
Last source activity
August 24, 2026 at 16:50
Detected SKILL.md language
English
Stars
5
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.