Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      20229116Updated Oct 1, 2024Oct 1, 2024
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      212117Updated Oct 1, 2024Oct 1, 2024
    • Apache License 2.0
      2726113Updated Oct 1, 2024Oct 1, 2024
    • Gives criticality score for an open source project
      Go
      Apache License 2.0
      1191.3k4129Updated Oct 1, 2024Oct 1, 2024
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      70254242Updated Sep 30, 2024Sep 30, 2024
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      47177325Updated Sep 30, 2024Sep 30, 2024
    • Website and API for OpenSSF Scorecard
      HTML
      Apache License 2.0
      2722307Updated Sep 30, 2024Sep 30, 2024
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      54371955Updated Sep 30, 2024Sep 30, 2024
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      4894.5k3418Updated Sep 30, 2024Sep 30, 2024
    • Feed parsing for language package manager updates
      Go
      Apache License 2.0
      24712110Updated Sep 30, 2024Sep 30, 2024
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1231.2k655Updated Sep 30, 2024Sep 30, 2024
    • tac

      Public
      Technical Advisory Council
      Other
      53108284Updated Sep 27, 2024Sep 27, 2024
    • Open Source Vulnerability schema.
      Python
      Apache License 2.0
      75177269Updated Sep 27, 2024Sep 27, 2024
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      1287334715Updated Sep 26, 2024Sep 26, 2024
    • artwork

      Public
      OpenSSF Artwork
      Apache License 2.0
      8701Updated Sep 24, 2024Sep 24, 2024
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      Apache License 2.0
      2570250Updated Sep 24, 2024Sep 24, 2024
    • Open Source Package Analysis
      Go
      Apache License 2.0
      48721578Updated Sep 10, 2024Sep 10, 2024
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      4980516Updated Sep 8, 2024Sep 8, 2024
    • OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Issues.
      Other
      1049144Updated Sep 5, 2024Sep 5, 2024
    • Potential WG on Artificial Intelligence and Machine Learning (AI/ML)
      Apache License 2.0
      85050Updated Aug 28, 2024Aug 28, 2024
    • s2c2f

      Public
      The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
      Other
      2417951Updated Aug 27, 2024Aug 27, 2024
    • Apache License 2.0
      121751Updated Aug 22, 2024Aug 22, 2024
    • Apache License 2.0
      10150Updated Aug 14, 2024Aug 14, 2024
    • Helping allocate resources to secure the critical open source projects we all depend on.
      Apache License 2.0
      36326210Updated Aug 1, 2024Aug 1, 2024
    • .github

      Public
      Github configuration
      2102Updated Aug 1, 2024Aug 1, 2024
    • staff

      Public
      Repository to keep track of staff operations
      Shell
      Apache License 2.0
      1030Updated Jul 31, 2024Jul 31, 2024
    • community

      Public
      Creative Commons Attribution 4.0 International
      5721Updated Jul 31, 2024Jul 31, 2024
    • The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
      Apache License 2.0
      40177240Updated Jul 24, 2024Jul 24, 2024
    • OpenSSF Working Group on Securing Software Repositories
      Other
      188863Updated Jul 11, 2024Jul 11, 2024
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      631122Updated Jun 27, 2024Jun 27, 2024