Skip to content
Change the repository type filter

All

    Repositories list

    • pvtr-github-repo-scanner

      Public
      Privateer plugin for scanning the security hygiene of a GitHub repository.
      Go
      Apache License 2.0
      1221215Updated Apr 9, 2026Apr 9, 2026
    • security-baseline

      Public
      Go
      Apache License 2.0
      38149577Updated Apr 9, 2026Apr 9, 2026
    • malicious-packages

      Public
      A repository of reports of malicious packages identified in Open Source package repositories, consumable via the Open Source Vulnerability (OSV) format.
      Go
      Apache License 2.0
      83486217Updated Apr 9, 2026Apr 9, 2026
    • tac

      Public
      Technical Advisory Council
      Other
      771403919Updated Apr 9, 2026Apr 9, 2026
    • cve-bin-tool

      Public
      The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl…
      Python
      GNU General Public License v3.0
      6131.7k14350Updated Apr 9, 2026Apr 9, 2026
    • oss-crs

      Public
      oss-crs
      Python
      MIT License
      443306Updated Apr 9, 2026Apr 9, 2026
    • scorecard-webapp

      Public
      Website and API for OpenSSF Scorecard
      Go
      Apache License 2.0
      30283228Updated Apr 8, 2026Apr 8, 2026
    • scorecard-action

      Public
      Official GitHub Action for OpenSSF Scorecard.
      Go
      Apache License 2.0
      843693016Updated Apr 8, 2026Apr 8, 2026
    • osv-schema

      Public
      Open Source Vulnerability schema.
      Go
      Apache License 2.0
      1152434910Updated Apr 8, 2026Apr 8, 2026
    • allstar

      Public
      GitHub App to set and enforce security policies
      Go
      Apache License 2.0
      1441.4k612Updated Apr 8, 2026Apr 8, 2026
    • scorecard

      Public
      OpenSSF Scorecard - Security health metrics for Open Source
      Go
      Apache License 2.0
      6235.4k36536Updated Apr 8, 2026Apr 8, 2026
    • alpha-omega

      Public
      Our mission is to catalyze sustainable improvements to critical open source software projects and ecosystems.
      Open Policy Agent
      Apache License 2.0
      6312102Updated Apr 8, 2026Apr 8, 2026
    • security-insights

      Public
      Machine-readable specification for the attestation of security-relevant data.
      Go
      Other
      167352Updated Apr 8, 2026Apr 8, 2026
    • Secure Software Development Fundamentals courses (from the OpenSSF Best Practices WG)
      CSS
      Creative Commons Attribution 4.0 International
      51202342Updated Apr 7, 2026Apr 7, 2026
    • wg-best-practices-os-developers

      Public
      The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
      JavaScript
      Apache License 2.0
      1921k8315Updated Apr 7, 2026Apr 7, 2026
    • ossf-landscape

      Public
      Apache License 2.0
      283101Updated Apr 6, 2026Apr 6, 2026
    • OpenSSF Working Group on Securing Software Repositories
      Other
      30128114Updated Apr 6, 2026Apr 6, 2026
    • glossary

      Public
      A reference for common terms when talking about OpenSSF and open source software security.
      JavaScript
      Apache License 2.0
      6442Updated Apr 6, 2026Apr 6, 2026
    • wg-globalcyberpolicy

      Public
      Global Cyber Policy Working Group
      Apache License 2.0
      20109150Updated Apr 2, 2026Apr 2, 2026
    • si-tooling

      Public
      Python
      Apache License 2.0
      4822Updated Mar 30, 2026Mar 30, 2026
    • Fuzz Introspector -- introspect, extend and optimise fuzzers
      Python
      Apache License 2.0
      8345410810Updated Mar 30, 2026Mar 30, 2026
    • scorecard-monitor

      Public
      Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
      JavaScript
      Apache License 2.0
      14471310Updated Mar 28, 2026Mar 28, 2026
    • wg-orbit

      Public
      ORBIT: Open Resources for Baselines, Interoperability, and Tooling
      Apache License 2.0
      42271Updated Mar 19, 2026Mar 19, 2026
    • artwork

      Public
      OpenSSF Artwork
      Apache License 2.0
      10800Updated Mar 17, 2026Mar 17, 2026
    • toolbelt

      Public
      Apache License 2.0
      62600Updated Mar 17, 2026Mar 17, 2026
    • orbit-launchpad

      Public
      Apache License 2.0
      1221Updated Mar 8, 2026Mar 8, 2026
    • SIRT

      Public
      The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Wor…
      Apache License 2.0
      61021Updated Mar 1, 2026Mar 1, 2026
    • sbom-everywhere

      Public
      Improve Software Bill of Materials (SBOM) tooling and training to encourage adoption
      Vue
      Apache License 2.0
      411132314Updated Feb 28, 2026Feb 28, 2026
    • package-analysis

      Public
      Open Source Package Analysis
      Go
      Apache License 2.0
      648736617Updated Feb 27, 2026Feb 27, 2026
    • security-assessments

      Public
      Apache License 2.0
      71872Updated Feb 26, 2026Feb 26, 2026
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.