Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      41313128Updated Jun 18, 2025Jun 18, 2025
    • Machine-readable specification for the attestation of security-relevant data.
      CUE
      Other
      1459111Updated Jun 18, 2025Jun 18, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      734181021Updated Jun 18, 2025Jun 18, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      74308264Updated Jun 17, 2025Jun 17, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      5464.9k3586Updated Jun 17, 2025Jun 17, 2025
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      164884659Updated Jun 17, 2025Jun 17, 2025
    • Apache License 2.0
      272900Updated Jun 17, 2025Jun 17, 2025
    • Model Signing Specification
      Apache License 2.0
      0000Updated Jun 16, 2025Jun 16, 2025
    • Go
      Apache License 2.0
      2688343Updated Jun 16, 2025Jun 16, 2025
    • tac

      Public
      Technical Advisory Council
      Other
      67125267Updated Jun 16, 2025Jun 16, 2025
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      Apache License 2.0
      3323Updated Jun 16, 2025Jun 16, 2025
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      52197342Updated Jun 14, 2025Jun 14, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      Apache License 2.0
      3593225Updated Jun 13, 2025Jun 13, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      51619Updated Jun 12, 2025Jun 12, 2025
    • Global Cyber Policy Working Group
      Apache License 2.0
      967101Updated Jun 11, 2025Jun 11, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      58105521Updated Jun 11, 2025Jun 11, 2025
    • toolbelt

      Public
      Apache License 2.0
      52000Updated Jun 10, 2025Jun 10, 2025
    • Python
      Apache License 2.0
      3511Updated Jun 10, 2025Jun 10, 2025
    • artwork

      Public
      OpenSSF Artwork
      Apache License 2.0
      9900Updated Jun 9, 2025Jun 9, 2025
    • Website and API for OpenSSF Scorecard
      HTML
      Apache License 2.0
      28243411Updated Jun 9, 2025Jun 9, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1251.3k724Updated Jun 9, 2025Jun 9, 2025
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      Apache License 2.0
      41351Updated Jun 7, 2025Jun 7, 2025
    • education

      Public
      OpenSSF Education SIG
      Apache License 2.0
      151730Updated May 28, 2025May 28, 2025
    • SIRT

      Public
      The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Working Group that is focused on creating secure vulnerability management capabilities within the open source ecosystem to ensure effective coordinated vulnerability disclosure practices (CVD)
      Apache License 2.0
      6920Updated May 27, 2025May 27, 2025
    • OpenSSF Working Group on Securing Software Repositories
      Other
      21107243Updated May 27, 2025May 27, 2025
    • Open Source Vulnerability schema.
      Go
      Apache License 2.0
      952022911Updated May 27, 2025May 27, 2025
    • s2c2f

      Public
      The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
      Other
      2720860Updated May 26, 2025May 26, 2025
    • Reliable Software Decomposition SIG
      Apache License 2.0
      0000Updated May 20, 2025May 20, 2025
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      1435136Updated May 15, 2025May 15, 2025
    • Helping allocate resources to secure the critical open source projects we all depend on.
      Apache License 2.0
      42355220Updated May 8, 2025May 8, 2025