Modules§
- agent_
spec_ conformance - branch_
history_ integrity - branch_
protection_ enforcement - build_
isolation - build_
provenance - change_
request_ size - code_
scanning_ alerts_ resolved - codeowners_
coverage - container_
provenance - container_
signature - conventional_
title - coverage_
threshold - dependency_
completeness - dependency_
provenance - dependency_
signature - dependency_
signer_ verified - description_
quality - harness_
gate - hosted_
build_ platform - issue_
linkage - license_
compliance - mcp_
scope_ check - merge_
commit_ policy - network_
egress_ audit - privileged_
operation_ audit - privileged_
workflow_ detection - provenance_
authenticity - release_
asset_ attestation - release_
traceability - required_
status_ checks - review_
independence - sbom_
completeness - scoped_
change - secret_
scanning - security_
file_ change - security_
policy - security_
test_ in_ ci - source_
authenticity - stale_
review - test_
coverage - two_
party_ review - vulnerability_
scanning
Functions§
- aiops_
controls - Returns AI-ops agent safety controls (Layers 1, 2, 4).
- all_
controls - Returns all controls (all SLSA + compliance + aiops).
- all_
slsa_ controls - Returns all SLSA controls (Source L4 + Build L3 + Dependencies L4).
- compliance_
controls - Returns compliance controls (non-SLSA, SOC2/ASPM mapped).
- control_
description - Returns the SARIF-friendly description for a built-in control ID. Falls back to “Custom control” for unknown IDs.
- posture_
controls - Returns repository-posture controls only (no PR-scoped compliance controls).
- slsa_
controls - Returns all SLSA controls across both tracks up to the given levels.
- slsa_
controls_ for_ level - Returns all SLSA controls required for the given track up to the given level.