TILLFORGE · SUPPLY CHAIN

See what every check covers, and what it can stop.

GA

Scans only help where they run and where someone acts on them. The supply chain map puts every repository in a row and every check in a column, so a repository with no SBOM, a secret check nobody requires, or a production environment anyone can ship to shows up before it matters.

01Coverage

One row per repository

Each cell reads the newest scan of the repository’s default branch, so a scan of a feature branch never makes a repository look covered. A cell is covered when the check ran and finished, partial when it is running, failed to run or only half applies, and none when it does not run at all. Covered cells also say whether the check passed.

ColumnWhat it reads
SourceThe default branch’s newest source record: covered at SLSA Source Level 3 or above once signed, partial below it with what the next level needs.
DependenciesThe default branch’s SBOM and its vulnerability scan, against your dependency policy and exceptions.
SecretsThe default branch’s secret scan.
CodeThe default branch’s code scan, against your code bar.
InfrastructureThe default branch’s IaC scan of its Terraform, CloudFormation and Kubernetes files, against your IaC bar. A repository with no infrastructure files says so, rather than being called clean.
ProvenanceWhether the newest CI build that declares outputs has signed provenance.
Deploy gatesWhether every production environment TillForge deploys to needs approvals, and how many checks can block a deploy.

Each cell is also marked with what a failure stops. M means it blocks merges into the default branch, from your dependency, code or IaC policy or a branch rule that requires the secret check. D means it blocks deployments, from the deploy policy. Without either mark, a failure is reported but nothing waits for it.

bash
# Every repository you can read, one column per check.
tilldev forge coverage

# Only repositories with a gap or a failing check, with the detail of each cell.
tilldev forge coverage --gaps --json

# The deploy policy, and making a check block (owners and admins).
tilldev forge deploy policy
tilldev forge deploy policy --rule supply-0002=block --rule supply-0004=block

The map shows up to 500 active repositories, by name, and only the ones you can read. Archived repositories are left out.

02Deploy policy

Hold a deploy on what the scans found

The deploy policy sets each check to off, warn or block for deploys TillForge runs, on production environments or on every environment. Block holds a deploy until its commit passes; a check still running holds it for up to 60 minutes and then blocks it. The deployments guide lists the checks and how approvals come first.

Deploys made elsewhere
An environment with no provider only records deploys your own pipeline makes, so neither approvals nor the policy can hold them. The map shows such a production environment as partial, so the gap stays visible.

Next: Deployments for approvals, or Provenance for signed builds. Back to the TillForge overview.