Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      995172310Updated May 26, 2026May 26, 2026
    • tac

      Public
      Technical Advisory Council
      Other
      831443716Updated May 26, 2026May 26, 2026
    • oss-crs

      Public
      Cyber Reasoning Systems for Bug-Finding and Patching in Open Source Software
      Python
      MIT License
      1187285Updated May 26, 2026May 26, 2026
    • The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl…
      Python
      GNU General Public License v3.0
      6201.7k14653Updated May 26, 2026May 26, 2026
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      853803018Updated May 26, 2026May 26, 2026
    • Python
      Apache License 2.0
      4922Updated May 26, 2026May 26, 2026
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      8545510910Updated May 26, 2026May 26, 2026
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1461.4k582Updated May 25, 2026May 25, 2026
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      Apache License 2.0
      6443Updated May 25, 2026May 25, 2026
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      6505.5k36837Updated May 25, 2026May 25, 2026
    • Privateer plugin for scanning the security hygiene of a GitHub repository.
      Go
      Apache License 2.0
      14232412Updated May 25, 2026May 25, 2026
    • Open Source Package Analysis
      Go
      Apache License 2.0
      698906510Updated May 25, 2026May 25, 2026
    • Open Source Vulnerability schema.
      Go
      Apache License 2.0
      115252506Updated May 25, 2026May 25, 2026
    • Website and API for OpenSSF Scorecard
      Go
      Apache License 2.0
      30283233Updated May 23, 2026May 23, 2026
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      51203344Updated May 22, 2026May 22, 2026
    • Go
      Apache License 2.0
      40154575Updated May 22, 2026May 22, 2026
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      1991k8215Updated May 20, 2026May 20, 2026
    • Apache License 2.0
      283100Updated May 20, 2026May 20, 2026
    • Python
      Apache License 2.0
      0206Updated May 19, 2026May 19, 2026
    • wg-bear

      Public
      The BEAR (Belonging, Empowerment, Allyship, and Representation) WG, formerly DEI, was formed in December 2023 to enhance representation and cybersecurity workfo…
      Apache License 2.0
      713102Updated May 18, 2026May 18, 2026
    • Model Signing Specification
      Python
      Apache License 2.0
      41633Updated May 15, 2026May 15, 2026
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      719115Updated May 14, 2026May 14, 2026
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      6412800Updated May 12, 2026May 12, 2026
    • Apache License 2.0
      1101Updated May 11, 2026May 11, 2026
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      1548146Updated May 11, 2026May 11, 2026
    • Machine-readable specification for the attestation of security-relevant data.
      Go
      Other
      177582Updated May 11, 2026May 11, 2026
    • Apache License 2.0
      71871Updated May 8, 2026May 8, 2026
    • Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      Apache License 2.0
      27169110Updated May 1, 2026May 1, 2026
    • .github

      Public
      Github configuration
      7201Updated Apr 27, 2026Apr 27, 2026
    • Global Cyber Policy Working Group
      Apache License 2.0
      21114170Updated Apr 21, 2026Apr 21, 2026
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.