Skip to content
Change the repository type filter

All

    Repositories list

    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      4527Updated Nov 16, 2025Nov 16, 2025
    • Website and API for OpenSSF Scorecard
      Go
      31283111Updated Nov 15, 2025Nov 15, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      79340261Updated Nov 15, 2025Nov 15, 2025
    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      64401116Updated Nov 15, 2025Nov 15, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      38105226Updated Nov 15, 2025Nov 15, 2025
    • education

      Public
      OpenSSF Education SIG
      161842Updated Nov 15, 2025Nov 15, 2025
    • SIRT

      Public
      The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Working Group that is focused on creating secure vulnerability management capabilities within the open source ecosystem to ensure effective coordinated vulnerability disclosure practices (CVD)
      61021Updated Nov 15, 2025Nov 15, 2025
    • A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
      4213051Updated Nov 15, 2025Nov 15, 2025
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      1839486610Updated Nov 15, 2025Nov 15, 2025
    • Go
      32117504Updated Nov 14, 2025Nov 14, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      5815.1k3612Updated Nov 14, 2025Nov 14, 2025
    • gemara

      Public
      Minimizing rework for governance activities.
      Go
      1528274Updated Nov 14, 2025Nov 14, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      618110Updated Nov 14, 2025Nov 14, 2025
    • OpenSSF Working Group on Securing Software Repositories
      25122214Updated Nov 13, 2025Nov 13, 2025
    • Open Source Vulnerability schema.
      Go
      1052153510Updated Nov 12, 2025Nov 12, 2025
    • tac

      Public
      Technical Advisory Council
      72133349Updated Nov 12, 2025Nov 12, 2025
    • 273001Updated Nov 11, 2025Nov 11, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      1431.4k590Updated Nov 10, 2025Nov 10, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      6111003Updated Nov 3, 2025Nov 3, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      764331032Updated Nov 3, 2025Nov 3, 2025
    • Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      2012071Updated Oct 17, 2025Oct 17, 2025
    • wg-vulnerability-disclosures

      Public
      The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
      42203340Updated Oct 1, 2025Oct 1, 2025
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      42090Updated Sep 29, 2025Sep 29, 2025
    • artwork

      Public
      OpenSSF Artwork
      10900Updated Sep 18, 2025Sep 18, 2025
    • Machine-readable specification for the attestation of security-relevant data.
      CUE
      1463101Updated Sep 16, 2025Sep 16, 2025
    • OpenSSF Governance and Legal Docs
      177300Updated Sep 9, 2025Sep 9, 2025
    • 41562Updated Aug 28, 2025Aug 28, 2025
    • wg-globalcyberpolicy

      Public
      Global Cyber Policy Working Group
      1794101Updated Aug 20, 2025Aug 20, 2025
    • .github

      Public
      Github configuration
      5201Updated Aug 14, 2025Aug 14, 2025
    • 1731130Updated Aug 14, 2025Aug 14, 2025