Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      2928790Updated Feb 4, 2025Feb 4, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      41419Updated Feb 4, 2025Feb 4, 2025
    • Apache License 2.0
      262711Updated Feb 4, 2025Feb 4, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      70277293Updated Feb 3, 2025Feb 3, 2025
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      141810525Updated Feb 3, 2025Feb 3, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      5388525Updated Feb 3, 2025Feb 3, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      60394988Updated Feb 3, 2025Feb 3, 2025
    • Website and API for OpenSSF Scorecard
      HTML
      Apache License 2.0
      2723317Updated Feb 3, 2025Feb 3, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      5134.8k3446Updated Feb 3, 2025Feb 3, 2025
    • Open Source Vulnerability schema.
      Python
      Apache License 2.0
      891902711Updated Feb 3, 2025Feb 3, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1241.3k682Updated Feb 2, 2025Feb 2, 2025
    • Open Source Package Analysis
      Go
      Apache License 2.0
      548116010Updated Feb 1, 2025Feb 1, 2025
    • Global Cyber Policy Working Group
      Apache License 2.0
      41530Updated Jan 31, 2025Jan 31, 2025
    • s2c2f

      Public
      The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
      Other
      2619550Updated Jan 31, 2025Jan 31, 2025
    • Go
      Apache License 2.0
      13143012Updated Jan 30, 2025Jan 30, 2025
    • Gives criticality score for an open source project
      Go
      Apache License 2.0
      1201.4k4133Updated Jan 30, 2025Jan 30, 2025
    • tac

      Public
      Technical Advisory Council
      Other
      61115236Updated Jan 29, 2025Jan 29, 2025
    • glossary

      Public
      JavaScript
      Apache License 2.0
      1101Updated Jan 29, 2025Jan 29, 2025
    • .github

      Public
      Github configuration
      3100Updated Jan 29, 2025Jan 29, 2025
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      1332134Updated Jan 25, 2025Jan 25, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      Apache License 2.0
      2677253Updated Jan 22, 2025Jan 22, 2025
    • OpenSSF Governance and Legal Docs
      Apache License 2.0
      197001Updated Jan 21, 2025Jan 21, 2025
    • A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
      Creative Commons Attribution 4.0 International
      4711940Updated Jan 16, 2025Jan 16, 2025
    • OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Issues.
      CUE
      Other
      105632Updated Jan 16, 2025Jan 16, 2025
    • wg-dei

      Public
      The Diversity, Equity, and Inclusion Working Group mission is to increase representation and strengthen the overall effectiveness of the cybersecurity workforce.
      Apache License 2.0
      1651Updated Jan 14, 2025Jan 14, 2025
    • Python
      Apache License 2.0
      1301Updated Jan 4, 2025Jan 4, 2025
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      47188341Updated Dec 10, 2024Dec 10, 2024
    • census

      Public
      📜Automated review of open source software projects
      HTML
      Other
      30116251Updated Dec 6, 2024Dec 6, 2024
    • Apache License 2.0
      122161Updated Dec 4, 2024Dec 4, 2024
    • Feed parsing for language package manager updates
      Go
      Apache License 2.0
      24762112Updated Dec 4, 2024Dec 4, 2024