Open Source Security Foundation (OpenSSF)
OpenSSF is a community of software developers and security engineers who are working together to secure open source software for the greater public good.
San Francisco, CA
Pinned Repositories
ai-ml-security
Working Group on Artificial Intelligence and Machine Learning (AI/ML) Security
allstar
GitHub App to set and enforce security policies
criticality_score
Gives criticality score for an open source project
foundation
OpenSSF Governance and Legal Docs
package-analysis
Open Source Package Analysis
scorecard
OpenSSF Scorecard - Security health metrics for Open Source
tac
Technical Advisory Council
wg-best-practices-os-developers
The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
wg-securing-critical-projects
Helping allocate resources to secure the critical open source projects we all depend on.
wg-securing-software-repos
OpenSSF Working Group on Securing Software Repositories
Open Source Security Foundation (OpenSSF)'s Repositories
ossf/criticality_score
Gives criticality score for an open source project
ossf/package-analysis
Open Source Package Analysis
ossf/wg-securing-critical-projects
Helping allocate resources to secure the critical open source projects we all depend on.
ossf/wg-metrics-and-metadata
The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed confidence in the security of open source projects. We do this by collecting, curating, and communicating relevant metrics and metadata from open source projects and the ecosystems of which they are a part.
ossf/s2c2f
The S2C2F Project is a group working within the OpenSSF's Supply Chain Integrity Working Group formed to further develop and continuously improve the S2C2F guide which outlines and defines how to securely consume Open Source Software (OSS) dependencies into the developer’s workflow.
ossf/wg-supply-chain-integrity
Our objective is to enable open source maintainers, contributors and end-users to understand and make decisions on the provenance of the code they maintain, produce and use.
ossf/oss-vulnerability-guide
A guide on coordinated vulnerability disclosure for open source projects. Includes templates for security policies (security.md) and disclosure notifications.
ossf/wg-securing-software-repos
OpenSSF Working Group on Securing Software Repositories
ossf/census
📜Automated review of open source software projects
ossf/security-reviews
A community collection of security reviews of open source software components.
ossf/package-feeds
Feed parsing for language package manager updates
ossf/Project-Security-Metrics
Collect, curate, and communicate relevant security metrics for open source projects.
ossf/scorecard-monitor
Simplify OpenSSF Scorecard tracking in your organization with automated markdown and JSON reports, plus optional GitHub issue alerts
ossf/wg-endusers
OpenSSF Endusers Working Group
ossf/DevRel-community
Evangelizing the mission and work of the OpenSSF and building strong community outreach around end-users, open-source maintainers, and contributors.
ossf/toolbelt
ossf/project-template
OpenSSF Project Template
ossf/education
OpenSSF Education SIG
ossf/OpenVEX
Vuln Disclosure WG's new SIG
ossf/Diagrammers-Society
OpenSSF Diagrammers Society
ossf/SIRT
The OSS-SIRT SIG (Open Source Software Security Incident Response Team Special Interest Group) is a group working within the OSSF's Vulnerability Disclosure Working Group that is focused on creating secure vulnerability management capabilities within the open source ecosystem to ensure effective coordinated vulnerability disclosure practices (CVD)
ossf/community
ossf/wg-bear
The BEAR (Belonging, Empowerment, Allyship, and Representation) WG, formerly DEI, was formed in December 2023 to enhance representation and cybersecurity workforce effectiveness.
ossf/S2C2F-attestation-schema-and-tool
Secure Supply Chain Consumption Framework (S2C2F) OSCAL Catalog and tool
ossf/disclosure-check
disclosure-check
ossf/si-tooling
ossf/scorecard-dependencyanalysis
Scorecard action for checking when new dependencies are added to the repository.
ossf/omega-moderne-client
ossf/staff
Repository to keep track of staff operations
ossf/reliable-software-decomposition
Reliable Software Decomposition SIG