Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      44316146Updated Jul 5, 2025Jul 5, 2025
    • Apache License 2.0
      272902Updated Jul 5, 2025Jul 5, 2025
    • Go
      Apache License 2.0
      2693344Updated Jul 4, 2025Jul 4, 2025
    • Machine-readable specification for the attestation of security-relevant data.
      CUE
      Other
      145991Updated Jul 4, 2025Jul 4, 2025
    • artwork

      Public
      OpenSSF Artwork
      Apache License 2.0
      10900Updated Jul 1, 2025Jul 1, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      58106521Updated Jul 1, 2025Jul 1, 2025
    • Global Cyber Policy Working Group
      Apache License 2.0
      107380Updated Jul 1, 2025Jul 1, 2025
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      1698896315Updated Jul 1, 2025Jul 1, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      516111Updated Jul 1, 2025Jul 1, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      75315262Updated Jul 1, 2025Jul 1, 2025
    • Open Source Vulnerability schema.
      Go
      Apache License 2.0
      96203299Updated Jul 1, 2025Jul 1, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      734201020Updated Jun 30, 2025Jun 30, 2025
    • Website and API for OpenSSF Scorecard
      HTML
      Apache License 2.0
      29243412Updated Jun 30, 2025Jun 30, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      5505k35414Updated Jun 30, 2025Jun 30, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1271.3k703Updated Jun 30, 2025Jun 30, 2025
    • tac

      Public
      Technical Advisory Council
      Other
      711262710Updated Jun 27, 2025Jun 27, 2025
    • Apache License 2.0
      1427130Updated Jun 26, 2025Jun 26, 2025
    • Model Signing Specification
      Apache License 2.0
      1000Updated Jun 24, 2025Jun 24, 2025
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      Apache License 2.0
      3323Updated Jun 23, 2025Jun 23, 2025
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      52197342Updated Jun 14, 2025Jun 14, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      Apache License 2.0
      3693226Updated Jun 13, 2025Jun 13, 2025
    • toolbelt

      Public
      Apache License 2.0
      52100Updated Jun 10, 2025Jun 10, 2025
    • Python
      Apache License 2.0
      3511Updated Jun 10, 2025Jun 10, 2025
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      Apache License 2.0
      41651Updated Jun 7, 2025Jun 7, 2025
    • education

      Public
      OpenSSF Education SIG
      Apache License 2.0
      151730Updated May 28, 2025May 28, 2025
    • SIRT

      Public
      The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Working Group that is focused on creating secure vulnerability management capabilities within the open source ecosystem to ensure effective coordinated vulnerability disclosure practices (CVD)
      Apache License 2.0
      61020Updated May 27, 2025May 27, 2025
    • OpenSSF Working Group on Securing Software Repositories
      Other
      21110303Updated May 27, 2025May 27, 2025
    • s2c2f

      Public
      The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
      Other
      2921060Updated May 26, 2025May 26, 2025
    • Reliable Software Decomposition SIG
      Apache License 2.0
      0000Updated May 20, 2025May 20, 2025
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      1435136Updated May 15, 2025May 15, 2025