Skip to main content

sscsb

Bootstrap and verify software supply chain security in a git repository using the `sscsb` CLI — secret scanning, commit signing policy, SBOMs, vulnerability scanning, SAST, dependency trust, SLSA provenance, and continuous posture, as 44 individually toggleable controls across five phases. USE WHEN harden this repo, supply chain security, SSCS, secret scanning, commit signing, SBOM, vulnerability scan, dependency trust, typosquat, SLSA provenance, sigstore, cosign, OpenSSF Scorecard, OpenVEX, SAST, branch protection, pin GitHub Actions, is this repo secure, set up security controls, sscsb, security baseline for a project. NOT FOR offensive security, pentesting, or exploit development; NOT FOR runtime threat detection, SIEM, or EDR; NOT FOR designing or implementing cryptographic primitives; NOT FOR general code review.

インストールへ移動

ソース情報

リポジトリ
p4gs/sscs-bootstrapper
ソースの最終更新活動
2026年8月24日 16:50
検出された SKILL.md の言語
英語
スター
5
フォーク
0

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。