Skip to main content

Module controls

Module controls 

Source

Modules§

actions_pinned_dependencies
branch_history_integrity
branch_protection_admin_enforcement
branch_protection_enforcement
build_isolation
build_provenance
change_request_size
code_scanning_alerts_resolved
codeowners_coverage
conventional_title
default_branch_settings_baseline
dependency_completeness
dependency_license_compliance
dependency_provenance
dependency_signature
dependency_signer_verified
dependency_update_tool
description_quality
dismiss_stale_reviews_on_push
environment_protection_rules
hosted_build_platform
issue_linkage
merge_commit_policy
privileged_workflow_detection
provenance_authenticity
release_asset_attestation
release_traceability
repository_permissions_audit
required_status_checks
review_independence
sbom_attestation
scoped_change
secret_scanning
secret_scanning_push_protection
security_file_change
security_policy
security_test_in_ci
source_authenticity
stale_review
test_coverage
two_party_review
vulnerability_scanning
workflow_permissions_restricted

Functions§

all_controls
Returns all controls (all SLSA + compliance).
all_slsa_controls
Returns all SLSA controls (Source L4 + Build L3 + Dependencies L4).
compliance_controls
Returns compliance controls (non-SLSA, SOC2/ASPM mapped).
control_description
Returns the SARIF-friendly description for a built-in control ID. Falls back to “Custom control” for unknown IDs.
posture_controls
Returns repository-posture controls only (no PR-scoped compliance controls).
slsa_controls
Returns all SLSA controls across both tracks up to the given levels.
slsa_controls_for_level
Returns all SLSA controls required for the given track up to the given level.