Skip to content
Change the repository type filter

All

    Repositories list

    • malicious-packages

      Public
      A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      100524236Updated May 30, 2026May 30, 2026
    • Privateer plugin for scanning the security hygiene of a GitHub repository.
      Go
      Apache License 2.0
      1423248Updated May 30, 2026May 30, 2026
    • Open Source Package Analysis
      Go
      Apache License 2.0
      698906511Updated May 30, 2026May 30, 2026
    • Rust
      Apache License 2.0
      1201Updated May 29, 2026May 29, 2026
    • tac

      Public
      Technical Advisory Council
      Other
      831443814Updated May 29, 2026May 29, 2026
    • The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl…
      Python
      GNU General Public License v3.0
      6201.7k14752Updated May 29, 2026May 29, 2026
    • oss-crs

      Public
      Cyber Reasoning Systems for Bug-Finding and Patching in Open Source Software
      Python
      MIT License
      12892912Updated May 28, 2026May 28, 2026
    • education

      Public
      OpenSSF Education SIG
      Apache License 2.0
      171841Updated May 28, 2026May 28, 2026
    • security-assessments

      Public
      Apache License 2.0
      71850Updated May 28, 2026May 28, 2026
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      719116Updated May 28, 2026May 28, 2026
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      854561099Updated May 27, 2026May 27, 2026
    • Go
      Apache License 2.0
      41155573Updated May 27, 2026May 27, 2026
    • Python
      Apache License 2.0
      4920Updated May 27, 2026May 27, 2026
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      853803018Updated May 26, 2026May 26, 2026
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1471.4k585Updated May 25, 2026May 25, 2026
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      Apache License 2.0
      7444Updated May 25, 2026May 25, 2026
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      6525.5k37142Updated May 25, 2026May 25, 2026
    • Open Source Vulnerability schema.
      Go
      Apache License 2.0
      116252507Updated May 25, 2026May 25, 2026
    • Website and API for OpenSSF Scorecard
      Go
      Apache License 2.0
      30283233Updated May 23, 2026May 23, 2026
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      51203344Updated May 22, 2026May 22, 2026
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      1991k8215Updated May 20, 2026May 20, 2026
    • Apache License 2.0
      283100Updated May 20, 2026May 20, 2026
    • Python
      Apache License 2.0
      0206Updated May 19, 2026May 19, 2026
    • wg-bear

      Public
      The BEAR (Belonging, Empowerment, Allyship, and Representation) WG, formerly DEI, was formed in December 2023 to enhance representation and cybersecurity workfo…
      Apache License 2.0
      713102Updated May 18, 2026May 18, 2026
    • Model Signing Specification
      Python
      Apache License 2.0
      41633Updated May 15, 2026May 15, 2026
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      6412902Updated May 12, 2026May 12, 2026
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      1548146Updated May 11, 2026May 11, 2026
    • Machine-readable specification for the attestation of security-relevant data.
      Go
      Other
      177582Updated May 11, 2026May 11, 2026
    • Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      Apache License 2.0
      27171110Updated May 1, 2026May 1, 2026
    • .github

      Public
      Github configuration
      7201Updated Apr 27, 2026Apr 27, 2026
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.