korext/Supply Chain Attestation Check

Scan supply chain AI provenance and enforce policy

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
max-ai-percentageMaximum weighted AI percentageno""
max-high-riskMaximum high risk dependenciesno""
min-coverageMinimum attestation coverageno""
block-ungoverned-aiFail if any HIGH or FULL AI dep lacks governancenofalse
require-attested-forGlob for deps requiring ATTESTED tierno""
ecosystemForce ecosystemno""
sbom-outputEmit SBOM: cyclonedx or spdxno""
private-registryPrivate registry URLno""
private-registry-tokenPrivate registry auth tokenno""
namedescription
weighted-ai-percentageCalculated weighted AI percentage
high-risk-countNumber of high risk dependencies found
coverageAttestation coverage percentage
sbom-pathPath to generated SBOM file
statusPolicy check status