Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      34297108Updated Mar 31, 2025Mar 31, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1271.3k702Updated Mar 31, 2025Mar 31, 2025
    • tac

      Public
      Technical Advisory Council
      Other
      641181915Updated Mar 31, 2025Mar 31, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      5244.8k34910Updated Mar 31, 2025Mar 31, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      515111Updated Mar 31, 2025Mar 31, 2025
    • Open Source Vulnerability schema.
      Python
      Apache License 2.0
      931962810Updated Mar 31, 2025Mar 31, 2025
    • Gives criticality score for an open source project
      Go
      Apache License 2.0
      1201.4k4237Updated Mar 31, 2025Mar 31, 2025
    • Apache License 2.0
      272800Updated Mar 30, 2025Mar 30, 2025
    • Machine-readable specification for the attestation of security-relevant data.
      CUE
      Other
      125761Updated Mar 30, 2025Mar 30, 2025
    • Apache License 2.0
      0000Updated Mar 29, 2025Mar 29, 2025
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      154842608Updated Mar 28, 2025Mar 28, 2025
    • Website and API for OpenSSF Scorecard
      HTML
      Apache License 2.0
      2723327Updated Mar 28, 2025Mar 28, 2025
    • Apache License 2.0
      132360Updated Mar 28, 2025Mar 28, 2025
    • Python
      Apache License 2.0
      3303Updated Mar 28, 2025Mar 28, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      73289261Updated Mar 27, 2025Mar 27, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      Apache License 2.0
      3086274Updated Mar 25, 2025Mar 25, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      5493524Updated Mar 24, 2025Mar 24, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      66408983Updated Mar 24, 2025Mar 24, 2025
    • glossary

      Public
      JavaScript
      Apache License 2.0
      1107Updated Mar 21, 2025Mar 21, 2025
    • Go
      Apache License 2.0
      2071201Updated Mar 20, 2025Mar 20, 2025
    • The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
      Apache License 2.0
      41186250Updated Mar 19, 2025Mar 19, 2025
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      50194342Updated Mar 13, 2025Mar 13, 2025
    • Open Source Package Analysis
      Go
      Apache License 2.0
      578236014Updated Mar 13, 2025Mar 13, 2025
    • wg-bear

      Public
      The BEAR (Belonging, Empowerment, Allyship, and Representation) WG, formerly DEI, was formed in December 2023 to enhance representation and cybersecurity workforce effectiveness.
      Apache License 2.0
      2652Updated Mar 1, 2025Mar 1, 2025
    • Global Cyber Policy Working Group
      Apache License 2.0
      73560Updated Feb 28, 2025Feb 28, 2025
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      1433136Updated Feb 15, 2025Feb 15, 2025
    • community

      Public
      Creative Commons Attribution 4.0 International
      5832Updated Feb 5, 2025Feb 5, 2025
    • s2c2f

      Public
      The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
      Other
      2620460Updated Jan 31, 2025Jan 31, 2025
    • .github

      Public
      Github configuration
      4101Updated Jan 29, 2025Jan 29, 2025
    • OpenSSF Governance and Legal Docs
      Apache License 2.0
      197201Updated Jan 21, 2025Jan 21, 2025
    68 repositories found. List is sorted by Last pushed in descending order.