OpenSSF Scorecard - Security health metrics for Open Source
-
Updated
Apr 20, 2026 - Go
OpenSSF Scorecard - Security health metrics for Open Source
Official GitHub Action for OpenSSF Scorecard.
Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
Dead code doesn't get patched. Detect abandoned & end-of-life dependencies that SCA tools miss — before they become the next xz-utils.
Tool for visualizing the Open SSF Scorecard Api data in a human friendly way
Audit your Gemfile for dependency health: maintenance activity, outdated versions, archived repos, OpenSSF scores, vulnerabilities, libyear drift, and composite health scores. Terminal, JSON, or markdown output with CI quality gates.
scir-oss is a tool that integrates public data and information regarding open source software projects and their products into a Project, Product, Protection, and Policy report (OSS-P4/R).
Scorecard action for checking when new dependencies are added to the repository.
OpenSSF Dashboard allows you to check the OpenSSF scorecards for entire organisations and users on GitHub or Gitlab.
Azure Pipelines Task for OpenSSF Scorecard
🔐 Repositories security and analysis.
FastMCP server that provides comprehensive security analysis for software packages across multiple ecosystems. It integrates seamlessly with Claude Desktop to provide AI-powered security evaluation capabilities.
An exporter for storing OpenSSF Scorecard data as Prometheus metrics.
Project to generate statistics about OpenSSF Compliance in the BEAM ecosystem.
Add a description, image, and links to the openssf-scorecard topic page so that developers can more easily learn about it.
To associate your repository with the openssf-scorecard topic, visit your repo's landing page and select "manage topics."