denzuko/cimatrix — org.cispec conformance

Verify org.cispec Change Item attribution conformance in binaries, Rego gates, and SLSA attestations.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Activelast commit Jul 2, 2026
License
None

Pinned Snippet

workflow.ymlSHA-pinned
uses: denzuko/cimatrix@cf855289cbb4650f689cd1a92a066b36f6efc3e8 # no releases — HEAD as of 2026-07-11

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
binaryPath to compiled binary for binaryno
gate-dirDirectory of .rego gate files for gateno
gate-fileSingle .rego gate file for gateno
gate-inputJSON input file for gate evaluationno
slsa-provenancePath to .intoto.jsonl provenance file for slsano
source-uriSource repository URI for SLSA verification (e.g. github.com/org/repo)no
builder-idSLSA builder ID URI (optional)no
sarif-outputPath to write SARIF report (uploaded as artefact)nocimatrix.sarif
offlineSkip remote gate bundle pull; use cached gates onlynofalse
cimatrix-versioncimatrix release version to installnolatest
namedescription
resultPASS or FAIL
violationsNumber of conformance violations found