Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      60383156Updated Oct 13, 2025Oct 13, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      79338261Updated Oct 13, 2025Oct 13, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      764311035Updated Oct 13, 2025Oct 13, 2025
    • Website and API for OpenSSF Scorecard
      HTML
      29253514Updated Oct 13, 2025Oct 13, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      38104223Updated Oct 13, 2025Oct 13, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      1391.4k602Updated Oct 13, 2025Oct 13, 2025
    • 273001Updated Oct 13, 2025Oct 13, 2025
    • gemara

      Public
      Minimizing rework for governance activities.
      Go
      1024240Updated Oct 13, 2025Oct 13, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      5755.1k3648Updated Oct 13, 2025Oct 13, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      618111Updated Oct 13, 2025Oct 13, 2025
    • Open Source Vulnerability schema.
      Python
      1012113513Updated Oct 12, 2025Oct 12, 2025
    • Go
      32111494Updated Oct 10, 2025Oct 10, 2025
    • tac

      Public
      Technical Advisory Council
      731313110Updated Oct 10, 2025Oct 10, 2025
    • Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      2011360Updated Oct 8, 2025Oct 8, 2025
    • education

      Public
      OpenSSF Education SIG
      151830Updated Oct 8, 2025Oct 8, 2025
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      1849316811Updated Oct 8, 2025Oct 8, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      6010802Updated Oct 6, 2025Oct 6, 2025
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      4526Updated Oct 6, 2025Oct 6, 2025
    • The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
      42201340Updated Oct 1, 2025Oct 1, 2025
    • OpenSSF Working Group on Securing Software Repositories
      24121214Updated Oct 1, 2025Oct 1, 2025
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      42090Updated Sep 29, 2025Sep 29, 2025
    • artwork

      Public
      OpenSSF Artwork
      10900Updated Sep 18, 2025Sep 18, 2025
    • Machine-readable specification for the attestation of security-relevant data.
      CUE
      1463101Updated Sep 16, 2025Sep 16, 2025
    • OpenSSF Governance and Legal Docs
      187300Updated Sep 9, 2025Sep 9, 2025
    • 41562Updated Aug 28, 2025Aug 28, 2025
    • Global Cyber Policy Working Group
      168990Updated Aug 20, 2025Aug 20, 2025
    • .github

      Public
      Github configuration
      5301Updated Aug 14, 2025Aug 14, 2025
    • 1731120Updated Aug 14, 2025Aug 14, 2025
    • Global CyberSecurity Skills Framework
      1420Updated Aug 13, 2025Aug 13, 2025
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      51196342Updated Jul 30, 2025Jul 30, 2025