Skip to content
Change the repository type filter

All

    Repositories list

    • A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      88499227Updated May 4, 2026May 4, 2026
    • The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl…
      Python
      GNU General Public License v3.0
      6191.7k14757Updated May 4, 2026May 4, 2026
    • Privateer plugin for scanning the security hygiene of a GitHub repository.
      Go
      Apache License 2.0
      1223217Updated May 4, 2026May 4, 2026
    • Apache License 2.0
      71871Updated May 3, 2026May 3, 2026
    • Apache License 2.0
      283103Updated May 3, 2026May 3, 2026
    • Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      6312501Updated May 1, 2026May 1, 2026
    • Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
      Apache License 2.0
      25167120Updated May 1, 2026May 1, 2026
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      6445.4k36427Updated Apr 29, 2026Apr 29, 2026
    • Website and API for OpenSSF Scorecard
      Go
      Apache License 2.0
      30283230Updated Apr 29, 2026Apr 29, 2026
    • oss-crs

      Public
      oss-crs
      Python
      MIT License
      660285Updated Apr 29, 2026Apr 29, 2026
    • Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      843763013Updated Apr 29, 2026Apr 29, 2026
    • Open Source Vulnerability schema.
      Go
      Apache License 2.0
      115247497Updated Apr 28, 2026Apr 28, 2026
    • tac

      Public
      Technical Advisory Council
      Other
      801433915Updated Apr 28, 2026Apr 28, 2026
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1451.4k580Updated Apr 28, 2026Apr 28, 2026
    • Python
      Apache License 2.0
      4920Updated Apr 28, 2026Apr 28, 2026
    • .github

      Public
      Github configuration
      7201Updated Apr 27, 2026Apr 27, 2026
    • Go
      Apache License 2.0
      40153573Updated Apr 27, 2026Apr 27, 2026
    • Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
      TypeScript
      Apache License 2.0
      618113Updated Apr 27, 2026Apr 27, 2026
    • Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      1448144Updated Apr 25, 2026Apr 25, 2026
    • The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      1951k7913Updated Apr 24, 2026Apr 24, 2026
    • Python
      Apache License 2.0
      0204Updated Apr 21, 2026Apr 21, 2026
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      8545410910Updated Apr 21, 2026Apr 21, 2026
    • Global Cyber Policy Working Group
      Apache License 2.0
      20112160Updated Apr 21, 2026Apr 21, 2026
    • A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
      Creative Commons Attribution 4.0 International
      4313751Updated Apr 20, 2026Apr 20, 2026
    • Machine-readable specification for the attestation of security-relevant data.
      Go
      Other
      177483Updated Apr 17, 2026Apr 17, 2026
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      Apache License 2.0
      6441Updated Apr 14, 2026Apr 14, 2026
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      51202343Updated Apr 10, 2026Apr 10, 2026
    • OpenSSF Working Group on Securing Software Repositories
      Other
      30127104Updated Apr 6, 2026Apr 6, 2026
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      Apache License 2.0
      42471Updated Mar 19, 2026Mar 19, 2026
    • artwork

      Public
      OpenSSF Artwork
      Apache License 2.0
      10800Updated Mar 17, 2026Mar 17, 2026
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.