Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      45321144Updated Jul 27, 2025Jul 27, 2025
    • The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
      42194312Updated Jul 24, 2025Jul 24, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      5605k36025Updated Jul 24, 2025Jul 24, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      77321262Updated Jul 24, 2025Jul 24, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      516111Updated Jul 24, 2025Jul 24, 2025
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      1728946212Updated Jul 24, 2025Jul 24, 2025
    • Website and API for OpenSSF Scorecard
      HTML
      29243412Updated Jul 23, 2025Jul 23, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      3795223Updated Jul 22, 2025Jul 22, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      734241021Updated Jul 21, 2025Jul 21, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      1301.3k704Updated Jul 21, 2025Jul 21, 2025
    • Go
      2798427Updated Jul 21, 2025Jul 21, 2025
    • Machine-readable specification for the attestation of security-relevant data.
      CUE
      145991Updated Jul 19, 2025Jul 19, 2025
    • Global CyberSecurity Skills Framework
      0000Updated Jul 18, 2025Jul 18, 2025
    • Open Source Vulnerability schema.
      Go
      97205339Updated Jul 18, 2025Jul 18, 2025
    • tac

      Public
      Technical Advisory Council
      721282713Updated Jul 16, 2025Jul 16, 2025
    • 273000Updated Jul 14, 2025Jul 14, 2025
    • 1528121Updated Jul 10, 2025Jul 10, 2025
    • Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      159740Updated Jul 9, 2025Jul 9, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      58107524Updated Jul 7, 2025Jul 7, 2025
    • OpenSSF Security Tooling Working Group
      52312180Updated Jul 6, 2025Jul 6, 2025
    • artwork

      Public
      OpenSSF Artwork
      10900Updated Jul 1, 2025Jul 1, 2025
    • Global Cyber Policy Working Group
      117791Updated Jul 1, 2025Jul 1, 2025
    • Model Signing Specification
      1110Updated Jun 24, 2025Jun 24, 2025
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      3423Updated Jun 23, 2025Jun 23, 2025
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      52196342Updated Jun 14, 2025Jun 14, 2025
    • toolbelt

      Public
      52100Updated Jun 10, 2025Jun 10, 2025
    • Python
      3511Updated Jun 10, 2025Jun 10, 2025
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      41661Updated Jun 7, 2025Jun 7, 2025
    • education

      Public
      OpenSSF Education SIG
      151730Updated May 28, 2025May 28, 2025
    • SIRT

      Public
      The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Working Group that is focused on creating secure vulnerability management capabilities within the open source ecosystem to ensure effective coordinated vulnerability disclosure practices (CVD)
      61020Updated May 27, 2025May 27, 2025