Skip to content
Change the repository type filter

All

    Repositories list

    • malicious-packages

      Public
      A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      71427147Updated Dec 28, 2025Dec 28, 2025
    • Machine-readable specification for the attestation of security-relevant data.
      Go
      156772Updated Dec 28, 2025Dec 28, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      5955.2k35916Updated Dec 27, 2025Dec 27, 2025
    • gemara

      Public
      Minimizing rework for governance activities.
      Go
      1734317Updated Dec 26, 2025Dec 26, 2025
    • wg-best-practices-os-developers

      Public
      The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      185968687Updated Dec 23, 2025Dec 23, 2025
    • tac

      Public
      Technical Advisory Council
      741343810Updated Dec 23, 2025Dec 23, 2025
    • Open Source Vulnerability schema.
      Go
      1092213512Updated Dec 22, 2025Dec 22, 2025
    • scorecard-action

      Public
      Official GitHub Action for OpenSSF Scorecard.
      Go
      81345287Updated Dec 22, 2025Dec 22, 2025
    • fuzz-introspector

      Public
      Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      784411066Updated Dec 22, 2025Dec 22, 2025
    • secure-sw-dev-fundamentals

      Public
      Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      52197343Updated Dec 22, 2025Dec 22, 2025
    • cve-bin-tool

      Public
      The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others), or if you know the components used, you can get a list of known vulnerabilities associated with an SBOM or a list of components and versions.
      Python
      5901.6k15664Updated Dec 22, 2025Dec 22, 2025
    • Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      22130100Updated Dec 19, 2025Dec 19, 2025
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      420110Updated Dec 18, 2025Dec 18, 2025
    • ossf-landscape

      Public
      273000Updated Dec 18, 2025Dec 18, 2025
    • wg-securing-software-repos

      Public
      OpenSSF Working Group on Securing Software Repositories
      28125114Updated Dec 18, 2025Dec 18, 2025
    • security-baseline

      Public
      Go
      34132569Updated Dec 17, 2025Dec 17, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      6211001Updated Dec 16, 2025Dec 16, 2025
    • Website and API for OpenSSF Scorecard
      Go
      31293116Updated Dec 15, 2025Dec 15, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      1451.4k603Updated Dec 15, 2025Dec 15, 2025
    • Global Cyber Policy Working Group
      1897112Updated Dec 3, 2025Dec 3, 2025
    • Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
      35195101Updated Dec 3, 2025Dec 3, 2025
    • wg-bear

      Public
      The BEAR (Belonging, Empowerment, Allyship, and Representation) WG, formerly DEI, was formed in December 2023 to enhance representation and cybersecurity workforce effectiveness.
      4983Updated Dec 2, 2025Dec 2, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      40111227Updated Dec 2, 2025Dec 2, 2025
    • Gives criticality score for an open source project
      Go
      1301.4k4535Updated Dec 2, 2025Dec 2, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      618112Updated Nov 27, 2025Nov 27, 2025
    • SIRT

      Public
      The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Working Group that is focused on creating secure vulnerability management capabilities within the open source ecosystem to ensure effective coordinated vulnerability disclosure practices (CVD)
      61020Updated Nov 20, 2025Nov 20, 2025
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      4529Updated Nov 19, 2025Nov 19, 2025
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      1441138Updated Nov 18, 2025Nov 18, 2025
    • education

      Public
      OpenSSF Education SIG
      171842Updated Nov 15, 2025Nov 15, 2025
    • A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
      4213351Updated Nov 15, 2025Nov 15, 2025