Skip to content
Change the repository type filter

All

    Repositories list

    • OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Issues.
      CUE
      Other
      105621Updated Feb 22, 2025Feb 22, 2025
    • Go
      Apache License 2.0
      1620322Updated Feb 21, 2025Feb 21, 2025
    • Global Cyber Policy Working Group
      Apache License 2.0
      62940Updated Feb 21, 2025Feb 21, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      72281261Updated Feb 21, 2025Feb 21, 2025
    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      30290103Updated Feb 21, 2025Feb 21, 2025
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      144819539Updated Feb 21, 2025Feb 21, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      63398980Updated Feb 21, 2025Feb 21, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1251.3k693Updated Feb 21, 2025Feb 21, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      51418Updated Feb 21, 2025Feb 21, 2025
    • Website and API for OpenSSF Scorecard
      HTML
      Apache License 2.0
      2723315Updated Feb 20, 2025Feb 20, 2025
    • glossary

      Public
      JavaScript
      Apache License 2.0
      1101Updated Feb 20, 2025Feb 20, 2025
    • Apache License 2.0
      132161Updated Feb 20, 2025Feb 20, 2025
    • Gives criticality score for an open source project
      Go
      Apache License 2.0
      1201.4k4134Updated Feb 20, 2025Feb 20, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      5214.8k3466Updated Feb 18, 2025Feb 18, 2025
    • tac

      Public
      Technical Advisory Council
      Other
      611162710Updated Feb 18, 2025Feb 18, 2025
    • The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
      Apache License 2.0
      41183261Updated Feb 18, 2025Feb 18, 2025
    • Apache License 2.0
      262710Updated Feb 18, 2025Feb 18, 2025
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      1333135Updated Feb 15, 2025Feb 15, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      5390520Updated Feb 12, 2025Feb 12, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      Apache License 2.0
      2678264Updated Feb 11, 2025Feb 11, 2025
    • Open Source Vulnerability schema.
      Python
      Apache License 2.0
      901912713Updated Feb 10, 2025Feb 10, 2025
    • community

      Public
      Creative Commons Attribution 4.0 International
      5832Updated Feb 5, 2025Feb 5, 2025
    • wg-dei

      Public
      The BEAR (Belonging, Empowerment, Allyship, and Representation) WG, formerly DEI, was formed in December 2023 to enhance representation and cybersecurity workforce effectiveness.
      Apache License 2.0
      1652Updated Feb 5, 2025Feb 5, 2025
    • Open Source Package Analysis
      Go
      Apache License 2.0
      558206010Updated Feb 1, 2025Feb 1, 2025
    • s2c2f

      Public
      The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
      Other
      2620060Updated Jan 31, 2025Jan 31, 2025
    • .github

      Public
      Github configuration
      3100Updated Jan 29, 2025Jan 29, 2025
    • OpenSSF Governance and Legal Docs
      Apache License 2.0
      197101Updated Jan 21, 2025Jan 21, 2025
    • A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
      Creative Commons Attribution 4.0 International
      4711940Updated Jan 16, 2025Jan 16, 2025
    • Python
      Apache License 2.0
      2301Updated Jan 4, 2025Jan 4, 2025
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      48188342Updated Dec 10, 2024Dec 10, 2024