Skip to content
Change the repository type filter

All

    Repositories list

    • malicious-packages

      Public
      A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      74454167Updated Feb 13, 2026Feb 13, 2026
    • 51773Updated Feb 12, 2026Feb 12, 2026
    • The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl…
      Python
      5991.6k15560Updated Feb 12, 2026Feb 12, 2026
    • security-baseline

      Public
      Go
      371405710Updated Feb 12, 2026Feb 12, 2026
    • 273100Updated Feb 12, 2026Feb 12, 2026
    • sbom-everywhere

      Public
      Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      411102311Updated Feb 11, 2026Feb 11, 2026
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      6311200Updated Feb 10, 2026Feb 10, 2026
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      823562813Updated Feb 10, 2026Feb 10, 2026
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      6045.3k36221Updated Feb 10, 2026Feb 10, 2026
    • osv-schema

      Public
      Open Source Vulnerability schema.
      Go
      110232476Updated Feb 9, 2026Feb 9, 2026
    • Website and API for OpenSSF Scorecard
      Go
      30283123Updated Feb 9, 2026Feb 9, 2026
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      794461076Updated Feb 9, 2026Feb 9, 2026
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      1441.4k610Updated Feb 9, 2026Feb 9, 2026
    • tac

      Public
      Technical Advisory Council
      751344015Updated Feb 9, 2026Feb 9, 2026
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      187988689Updated Feb 9, 2026Feb 9, 2026
    • 1000Updated Feb 6, 2026Feb 6, 2026
    • The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advoc…
      43211430Updated Feb 4, 2026Feb 4, 2026
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      14421310Updated Feb 4, 2026Feb 4, 2026
    • Machine-readable specification for the attestation of security-relevant data.
      Go
      167252Updated Feb 2, 2026Feb 2, 2026
    • Python
      3720Updated Feb 1, 2026Feb 1, 2026
    • wg-bear

      Public
      The BEAR (Belonging, Empowerment, Allyship, and Representation) WG, formerly DEI, was formed in December 2023 to enhance representation and cybersecurity workfo…
      51282Updated Jan 26, 2026Jan 26, 2026
    • Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, pro…
      36196101Updated Jan 15, 2026Jan 15, 2026
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      42160Updated Jan 3, 2026Jan 3, 2026
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      51200343Updated Dec 22, 2025Dec 22, 2025
    • Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      2214590Updated Dec 19, 2025Dec 19, 2025
    • OpenSSF Working Group on Securing Software Repositories
      29127114Updated Dec 18, 2025Dec 18, 2025
    • Global Cyber Policy Working Group
      19102132Updated Dec 3, 2025Dec 3, 2025
    • Gives criticality score for an open source project
      Go
      1301.4k4535Updated Dec 2, 2025Dec 2, 2025
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      618112Updated Nov 27, 2025Nov 27, 2025
    • SIRT

      Public
      The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Wor…
      61020Updated Nov 20, 2025Nov 20, 2025