See what every check covers, and what it can stop.
GAScans only help where they run and where someone acts on them. The supply chain map puts every repository in a row and every check in a column, so a repository with no SBOM, a secret check nobody requires, or a production environment anyone can ship to shows up before it matters.
One row per repository
Each cell reads the newest scan of the repository’s default branch, so a scan of a feature branch never makes a repository look covered. A cell is covered when the check ran and finished, partial when it is running, failed to run or only half applies, and none when it does not run at all. Covered cells also say whether the check passed.
| Column | What it reads |
|---|---|
| Source | The default branch’s newest source record: covered at SLSA Source Level 3 or above once signed, partial below it with what the next level needs. |
| Dependencies | The default branch’s SBOM and its vulnerability scan, against your dependency policy and exceptions. |
| Secrets | The default branch’s secret scan. |
| Code | The default branch’s code scan, against your code bar. |
| Infrastructure | The default branch’s IaC scan of its Terraform, CloudFormation and Kubernetes files, against your IaC bar. A repository with no infrastructure files says so, rather than being called clean. |
| Provenance | Whether the newest CI build that declares outputs has signed provenance. |
| Deploy gates | Whether every production environment TillForge deploys to needs approvals, and how many checks can block a deploy. |
Each cell is also marked with what a failure stops. M means it blocks merges into the default branch, from your dependency, code or IaC policy or a branch rule that requires the secret check. D means it blocks deployments, from the deploy policy. Without either mark, a failure is reported but nothing waits for it.
# Every repository you can read, one column per check.
tilldev forge coverage
# Only repositories with a gap or a failing check, with the detail of each cell.
tilldev forge coverage --gaps --json
# The deploy policy, and making a check block (owners and admins).
tilldev forge deploy policy
tilldev forge deploy policy --rule supply-0002=block --rule supply-0004=blockThe map shows up to 500 active repositories, by name, and only the ones you can read. Archived repositories are left out.
Hold a deploy on what the scans found
The deploy policy sets each check to off, warn or block for deploys TillForge runs, on production environments or on every environment. Block holds a deploy until its commit passes; a check still running holds it for up to 60 minutes and then blocks it. The deployments guide lists the checks and how approvals come first.
Next: Deployments for approvals, or Provenance for signed builds. Back to the TillForge overview.