brandonjsellam-releone/TRELYAN Post-Quantum Readiness Scorecard

Scan your repo for quantum-vulnerable crypto: A–F readiness grade + CycloneDX CBOM, and fail the build on broken crypto.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
pathDirectory to scanno.
fail-onComma-separated risk classes that fail the build (e.g. broken-classical,quantum-broken)nobroken-classical
min-gradeMinimum acceptable grade (A–F); build fails below it. Empty = no grade gate.no""
excludeComma-separated path globs to exclude (e.g. test-fixtures/,examples/,**/*.golden). Also readable from .pqcbomignore lines containing "/" or prefixed "path:". Excluded paths are counted in the step summary, never silently dropped.no""
namedescription
gradePost-Quantum Readiness grade (A–F)
scorePost-Quantum Readiness score (0–100)
sarif-filePath to the SARIF 2.1.0 report (upload via github/codeql-action/upload-sarif to populate the Security tab)
cbom-filePath to the CycloneDX CBOM (cbom.cdx.json)