CISA SSDF Attestation requirements — check your workflow against SSDF
Audit a GitHub Actions workflow against the four CISA secure software development attestation sections and the NIST SSDF practices behind them. Runs entirely in your browser — nothing is uploaded.
Free here: Audit the workflow file you have open and list every attestation gap with its SSDF practice ID and the CISA form section it sits under.. In the editor: Audit every workflow in the repository at once and export one dated evidence table mapped to all four attestation sections. — that part asks for a licence key.
Same engine as the VS Code extension, byte for byte.