Skip to content
Change the repository type filter

All

    Repositories list

    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      1859566610Updated Dec 6, 2025Dec 6, 2025
    • malicious-packages

      Public
      A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      66422104Updated Dec 5, 2025Dec 5, 2025
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      80339276Updated Dec 5, 2025Dec 5, 2025
    • ai-ml-security

      Public
      Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      22125100Updated Dec 5, 2025Dec 5, 2025
    • osv-schema

      Public
      Open Source Vulnerability schema.
      Go
      1082173510Updated Dec 5, 2025Dec 5, 2025
    • gemara

      Public
      Minimizing rework for governance activities.
      Go
      1730274Updated Dec 4, 2025Dec 4, 2025
    • security-baseline

      Public
      Go
      33120559Updated Dec 4, 2025Dec 4, 2025
    • wg-globalcyberpolicy

      Public
      Global Cyber Policy Working Group
      1895111Updated Dec 3, 2025Dec 3, 2025
    • Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
      35194101Updated Dec 3, 2025Dec 3, 2025
    • wg-bear

      Public
      The BEAR (Belonging, Empowerment, Allyship, and Representation) WG, formerly DEI, was formed in December 2023 to enhance representation and cybersecurity workforce effectiveness.
      41071Updated Dec 2, 2025Dec 2, 2025
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      764341044Updated Dec 2, 2025Dec 2, 2025
    • Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      38111227Updated Dec 2, 2025Dec 2, 2025
    • Gives criticality score for an open source project
      Go
      1291.4k4435Updated Dec 2, 2025Dec 2, 2025
    • Website and API for OpenSSF Scorecard
      Go
      31283114Updated Dec 1, 2025Dec 1, 2025
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      6111006Updated Dec 1, 2025Dec 1, 2025
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      1431.4k600Updated Dec 1, 2025Dec 1, 2025
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      5915.2k36313Updated Dec 1, 2025Dec 1, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      618112Updated Nov 27, 2025Nov 27, 2025
    • 273002Updated Nov 24, 2025Nov 24, 2025
    • SIRT

      Public
      The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Working Group that is focused on creating secure vulnerability management capabilities within the open source ecosystem to ensure effective coordinated vulnerability disclosure practices (CVD)
      61020Updated Nov 20, 2025Nov 20, 2025
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      4529Updated Nov 19, 2025Nov 19, 2025
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      1440138Updated Nov 18, 2025Nov 18, 2025
    • tac

      Public
      Technical Advisory Council
      73133387Updated Nov 17, 2025Nov 17, 2025
    • education

      Public
      OpenSSF Education SIG
      161842Updated Nov 15, 2025Nov 15, 2025
    • A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
      4113151Updated Nov 15, 2025Nov 15, 2025
    • OpenSSF Working Group on Securing Software Repositories
      27123114Updated Nov 13, 2025Nov 13, 2025
    • The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting and communication.
      43204350Updated Oct 1, 2025Oct 1, 2025
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      420100Updated Sep 29, 2025Sep 29, 2025
    • artwork

      Public
      OpenSSF Artwork
      10900Updated Sep 18, 2025Sep 18, 2025
    • Machine-readable specification for the attestation of security-relevant data.
      CUE
      1566101Updated Sep 16, 2025Sep 16, 2025