SSDF Attestation Audit for GitHub Actions

Audit a GitHub Actions workflow against the four CISA secure software development attestation sections and the NIST SSDF practices behind them. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the complete version $29

This page is the working piece. The full pack has everything below.

14 rules, four CISA attestation sections, one workflow file

A US application-security contractor bills roughly 150-250 an hour to review and re-pin a release pipeline by hand.

Buy the full version — $29

Questions people ask

What does the SSDF Attestation Audit actually do?

It reads a GitHub Actions workflow file and marks every line that contradicts the CISA Secure Software Development Attestation Common Form, naming the NIST SSDF (SP 800-218) practice ID and the form section behind each mark. It ships 14 rules across the four attestation sections. On the bundled AI-written deploy workflow it returns 8 findings; on the hardened release workflow it returns 0.

Who is this for?

Software vendors that sell to United States federal agencies, and the platform or release engineers who own their GitHub Actions pipelines. Under OMB M-22-18 and M-23-16 an agency may use your software only after a chief executive or a designated employee signs the attestation form. Those engineers are the people who have to produce the evidence under that signature.

Why can't I just ask a chatbot to harden my workflow?

A general assistant rewrites YAML confidently but does not tell you which attestation section is still empty afterwards. It will pin one action and leave provenance and SBOM missing, and it gives you no line number tied to PS.3.1 that an auditor can follow. This audit is a fixed, readable rule table, not a generated opinion that changes between prompts.

What is free and what does the full version add?

Free: audit the workflow file you have open and list every attestation gap with its practice ID and form section, all 14 rules, all four sections. That job finishes on its own. The full version changes the scope: it audits every workflow in the repository at once and exports one dated evidence table mapped to all four attestation sections.

What would this cost done by hand?

A United States application-security contractor bills roughly 150 to 250 an hour to review a release pipeline, re-pin actions to commit SHAs and map each control back to an SSDF practice. The full version is 29 once, one licence key per person or team seat, with a 7-day full refund. The free audit costs nothing.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.

Want the full version?
Enter your email and we send the download link.
ENDEJAESPT

Find a tool