Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      232551111Updated Nov 23, 2024Nov 23, 2024
    • Apache License 2.0
      272610Updated Nov 22, 2024Nov 22, 2024
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      5024.6k3407Updated Nov 22, 2024Nov 22, 2024
    • Gives criticality score for an open source project
      Go
      Apache License 2.0
      1191.3k4135Updated Nov 22, 2024Nov 22, 2024
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      56381954Updated Nov 21, 2024Nov 21, 2024
    • Website and API for OpenSSF Scorecard
      HTML
      Apache License 2.0
      2722319Updated Nov 21, 2024Nov 21, 2024
    • wg-dei

      Public
      The Diversity, Equity, and Inclusion Working Group mission is to increase representation and strengthen the overall effectiveness of the cybersecurity workforce.
      Apache License 2.0
      1451Updated Nov 21, 2024Nov 21, 2024
    • Feed parsing for language package manager updates
      Go
      Apache License 2.0
      24712112Updated Nov 21, 2024Nov 21, 2024
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1221.3k643Updated Nov 21, 2024Nov 21, 2024
    • Go
      Apache License 2.0
      73245Updated Nov 20, 2024Nov 20, 2024
    • Open Source Vulnerability schema.
      Python
      Apache License 2.0
      841862610Updated Nov 20, 2024Nov 20, 2024
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      133769519Updated Nov 19, 2024Nov 19, 2024
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      70267252Updated Nov 18, 2024Nov 18, 2024
    • tac

      Public
      Technical Advisory Council
      Other
      60109205Updated Nov 15, 2024Nov 15, 2024
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      312119Updated Nov 15, 2024Nov 15, 2024
    • The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
      Apache License 2.0
      40180240Updated Nov 13, 2024Nov 13, 2024
    • artwork

      Public
      OpenSSF Artwork
      Apache License 2.0
      8701Updated Nov 5, 2024Nov 5, 2024
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      5084513Updated Nov 4, 2024Nov 4, 2024
    • Open Source Package Analysis
      Go
      Apache License 2.0
      517355711Updated Nov 1, 2024Nov 1, 2024
    • Apache License 2.0
      121960Updated Oct 31, 2024Oct 31, 2024
    • OpenSSF Working Group on Securing Software Repositories
      Other
      199364Updated Oct 28, 2024Oct 28, 2024
    • Potential WG on Artificial Intelligence and Machine Learning (AI/ML)
      Apache License 2.0
      95330Updated Oct 23, 2024Oct 23, 2024
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      46180335Updated Oct 18, 2024Oct 18, 2024
    • Helping allocate resources to secure the critical open source projects we all depend on.
      Apache License 2.0
      40331220Updated Oct 10, 2024Oct 10, 2024
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      Apache License 2.0
      2672251Updated Sep 24, 2024Sep 24, 2024
    • OPENSSF SECURITY INSIGHTS: Repository for development of the draft standard, where requests for modification should be made via Github Issues.
      Other
      1050144Updated Sep 5, 2024Sep 5, 2024
    • s2c2f

      Public
      The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
      Other
      2419051Updated Aug 27, 2024Aug 27, 2024
    • .github

      Public
      Github configuration
      2102Updated Aug 1, 2024Aug 1, 2024
    • staff

      Public
      Repository to keep track of staff operations
      Shell
      Apache License 2.0
      1030Updated Jul 31, 2024Jul 31, 2024
    • community

      Public
      Creative Commons Attribution 4.0 International
      5731Updated Jul 31, 2024Jul 31, 2024